Vulnerability CVE-2020-20918


Published: 2023-06-20

Description:
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.

 References:
https://github.com/pluck-cms/pluck/issues/80

Copyright 2026, cxsecurity.com

 

Back to Top