10 High
AI Score
Confidence
High
0.003 Low
EPSS
Percentile
66.1%
An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess.
github.com/pluck-cms/pluck/commit/8f6541e60c9435e82e9c531a20cb3c218d36976e
github.com/pluck-cms/pluck/issues/58