CVE-2022-26589
Pluck CMS vulnerability analysis and mitigation

Overview

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Pluck CMS version 4.7.15, identified as CVE-2022-26589. The vulnerability allows attackers to delete arbitrary pages within the content management system when an authenticated administrator is tricked into executing malicious requests (NVD, MITRE).

Technical details

The vulnerability exists in the delete pages/trashcan feature of Pluck CMS v4.7.15. When an administrator is authenticated, the application fails to implement proper CSRF protections, allowing an attacker to forge requests that can delete any arbitrary page. The attack can be executed through a specially crafted HTML form that automatically submits POST requests to the target endpoint (Medium Blog).

Impact

If successfully exploited, an attacker can force an authenticated administrator to unknowingly delete any page on the Pluck CMS website. This could lead to loss of content and disruption of website operations (Medium Blog).

Mitigation and workarounds

Web applications should implement proper CSRF protections such as anti-CSRF tokens, checking referrer headers, and implementing proper session management. For Pluck CMS specifically, administrators should upgrade to a patched version if available, and exercise caution when clicking on links while authenticated to the CMS (OWASP).

Additional resources


SourceThis report was generated using AI

Related Pluck CMS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-43042CRITICAL9.8
  • Pluck CMSPluck CMS
  • cpe:2.3:a:pluck-cms:pluck
NoYesAug 16, 2024
CVE-2023-50564HIGH8.8
  • Pluck CMSPluck CMS
  • cpe:2.3:a:pluck-cms:pluck
NoYesDec 14, 2023
CVE-2025-46099HIGH7.2
  • Pluck CMSPluck CMS
  • cpe:2.3:a:pluck-cms:pluck
NoYesJul 23, 2025
CVE-2023-5013MEDIUM5.4
  • Pluck CMSPluck CMS
  • cpe:2.3:a:pluck-cms:pluck
NoYesSep 16, 2023
CVE-2024-9405MEDIUM5.3
  • Pluck CMSPluck CMS
  • cpe:2.3:a:pluck-cms:pluckcms
NoYesOct 01, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management