CVE-2022-26965 | Pluck 4.7.16 Theme Upload admin.php?action=themeinstall unrestricted upload (ID 166336 / EDB-50826)
A vulnerability was found in Pluck 4.7.16. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin.php?action=themeinstall of the component Theme Upload Handler. The manipulation leads to unrestricted upload.
This vulnerability is known as CVE-2022-26965. The attack can be launched remotely. Furthermore, there is an exploit available.