
Cloud Vulnerability DB
A community-led vulnerabilities database
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Pluck CMS version 4.7.15, identified as CVE-2022-26589. The vulnerability allows attackers to delete arbitrary pages within the content management system when an authenticated administrator is tricked into executing malicious requests (NVD, MITRE).
The vulnerability exists in the delete pages/trashcan feature of Pluck CMS v4.7.15. When an administrator is authenticated, the application fails to implement proper CSRF protections, allowing an attacker to forge requests that can delete any arbitrary page. The attack can be executed through a specially crafted HTML form that automatically submits POST requests to the target endpoint (Medium Blog).
If successfully exploited, an attacker can force an authenticated administrator to unknowingly delete any page on the Pluck CMS website. This could lead to loss of content and disruption of website operations (Medium Blog).
Web applications should implement proper CSRF protections such as anti-CSRF tokens, checking referrer headers, and implementing proper session management. For Pluck CMS specifically, administrators should upgrade to a patched version if available, and exercise caution when clicking on links while authenticated to the CMS (OWASP).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."