Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-21564
Pluck CMS vulnerability analysis and mitigation

Overview

An issue was discovered in Pluck CMS versions 4.7.10-dev2 and 4.7.11 that allows remote command execution via admin.php?action=files. The vulnerability was disclosed in August 2020 and assigned identifier CVE-2020-21564. The vulnerability affects the file management interface in the admin backend of Pluck CMS (MITRE).

Technical details

The vulnerability exists in the file upload functionality within the admin interface, specifically in /data/inc/file.php line 42. The issue occurs when handling file names like '.htaccess', where the strpos function returns 0, allowing for malicious file uploads. This can be exploited through the management file interface by uploading specially crafted files (GitHub Issue 83).

Impact

When successfully exploited, this vulnerability allows an attacker to achieve remote command execution on the affected system. The attacker can upload malicious files and execute arbitrary PHP code on the server, potentially leading to complete system compromise (GitHub Issue 83, GitHub Issue 91).

Exploitability

The vulnerability requires authentication to the admin interface before exploitation. A proof of concept exists demonstrating the attack through a series of steps: uploading a .htaccess file, manipulating it through the trash function, and then uploading shell code to achieve remote code execution (GitHub Issue 91).

Mitigation and workarounds

Users should upgrade to a version newer than 4.7.11 if available. If upgrading is not possible, administrators should carefully monitor and restrict access to the file management interface in the admin backend (MITRE).

Additional resources


SourceThis report was generated using AI

Related Pluck CMS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-43042CRITICAL9.8
  • Pluck CMS logoPluck CMS
  • cpe:2.3:a:pluck-cms:pluck
NoYesAug 16, 2024
CVE-2023-50564HIGH8.8
  • Pluck CMS logoPluck CMS
  • cpe:2.3:a:pluck-cms:pluck
NoYesDec 14, 2023
CVE-2025-46099HIGH7.2
  • Pluck CMS logoPluck CMS
  • cpe:2.3:a:pluck-cms:pluck
NoYesJul 23, 2025
CVE-2023-5013MEDIUM5.4
  • Pluck CMS logoPluck CMS
  • cpe:2.3:a:pluck-cms:pluck
NoYesSep 16, 2023
CVE-2024-9405MEDIUM5.3
  • Pluck CMS logoPluck CMS
  • cpe:2.3:a:pluck-cms:pluckcms
NoYesOct 01, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management