Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
The application does not implement any security mechanisms limiting multiple failed authentication attempts (CWE-307). An attacker can automatically send login requests with different password combinations without risking account lockout or process slowdown. As a result, a full brute force attack on the CMS administration panel is possible.
A successful brute force attack can lead to administrator account takeover, which consequently enables the attacker to have full control over the CMS system — including content modification, malicious file upload, or further server compromise.
Apply patches available from the vendor according to the references provided. As additional remedial measures, it is recommended to implement external login attempt restriction mechanisms (e.g., rate limiting at the firewall or web server level), use strong and unique administrator passwords, and consider restricting access to the login panel at the IP address level.
Pluck CMS version 4.7.18
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HPluck Cms Pluck
APPPluck-Cms4.7.18
Related vulnerabilities
Zip Slip w Pluck CMS — path traversal i zdalne wykonanie kodu
RCE w Pluck CMS poprzez niebezpieczne przesyłanie plików
Pluck CMS 4.7.8 — zdalne wykonanie kodu przez upload pliku .htaccess
Pluck CMS — upload i wykonanie dowolnego kodu PHP przez fałszywy typ MIME
Pluck CMS — zdalne wykonanie kodu PHP przez upload pliku .phtml/.htaccess