VYPR
Unrated severityNVD Advisory· Published Jul 23, 2025· Updated Jul 23, 2025

CVE-2025-46099

CVE-2025-46099

Description

In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.

Affected products

2
  • Pluck/Pluck CMSdescription
  • Pluck/Pluckllm-fuzzy
    Range: 4.7.20-dev

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.