{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/pluck-cms/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pluck-cms:pluck:4.7.18:-:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2023-50564"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Pluck (4.7.18)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","rce","file-upload","pluck-cms"],"_cs_type":"advisory","_cs_vendors":["Pluck CMS"],"content_html":"\u003cp\u003ePluck CMS version 4.7.18 contains an arbitrary file upload vulnerability (CVE-2023-50564) located in the \u003ccode\u003emodules_install.php\u003c/code\u003e component. This vulnerability is reachable by an authenticated user with access to the module installation functionality. By interacting with the \u003ccode\u003eadmin.php?action=installmodule\u003c/code\u003e endpoint, an attacker can upload a specially crafted ZIP archive containing a PHP payload. When the system processes the uploaded ZIP file, the included PHP file is saved to the server, allowing the attacker to trigger remote code execution (RCE). As of September 2026, multiple proof-of-concept exploits have been published, significantly lowering the barrier for exploitation. Defenders should restrict access to the administrative dashboard and ensure the instance is patched.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs authentication to obtain a valid session cookie for the Pluck CMS administration interface.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the module installation page at \u003ccode\u003eadmin.php?action=installmodule\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a ZIP file containing a malicious PHP web shell or payload.\u003c/li\u003e\n\u003cli\u003eAttacker sends an HTTP POST request to the \u003ccode\u003emodules_install.php\u003c/code\u003e script to upload the crafted ZIP file.\u003c/li\u003e\n\u003cli\u003eThe server-side code insecurely extracts the ZIP contents to a directory on the web server.\u003c/li\u003e\n\u003cli\u003eThe web server extracts the PHP payload file, potentially into a location accessible to the public web root.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the URL where the uploaded PHP file is stored.\u003c/li\u003e\n\u003cli\u003eWeb server executes the PHP payload, granting the attacker arbitrary code execution on the underlying host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2023-50564 results in full remote code execution on the target server. This enables attackers to steal sensitive application data, pivot deeper into the internal network, or deploy additional malware. Given the high CVSS score of 8.8, this flaw poses a critical risk to any infrastructure hosting unpatched versions of Pluck CMS 4.7.18.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Pluck CMS instances to the latest available version beyond 4.7.18.\u003c/li\u003e\n\u003cli\u003eImplement strict access control lists (ACLs) for the \u003ccode\u003eadmin.php\u003c/code\u003e endpoint to prevent unauthorized access by low-privileged users.\u003c/li\u003e\n\u003cli\u003eDeploy the provided webserver detection rule to monitor for malicious file upload patterns in application logs.\u003c/li\u003e\n\u003cli\u003eAudit the web server's upload directories to identify and remove unauthorized .php or .phtml files.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T17:57:16Z","date_published":"2026-09-16T17:57:16Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pluck-rce/","summary":"An authenticated arbitrary file upload vulnerability in Pluck CMS v4.7.18 allows remote attackers to achieve code execution by uploading a malicious ZIP archive via the module installation interface.","title":"Arbitrary File Upload and RCE in Pluck CMS via CVE-2023-50564","url":"https://feed.craftedsignal.io/briefs/2026-09-pluck-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Pluck CMS","version":"https://jsonfeed.org/version/1.1"}