VYPR
Critical severity9.6NVD Advisory· Published Aug 5, 2026· Updated Aug 28, 2026

CVE-2026-70376

CVE-2026-70376

Description

Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.