CVE-2026-54416: Pluck CMS: Unrestricted File Upload via Missing .php8 Extension in Upload Blacklist
Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.cgi','.phar'), checked against the last 4-5 characters of the filename. The blacklist omits the '.php8' extension. An authenticated administrator can upload a file named e.g. shell.php8, which is stored unmodified and, on servers running PHP 8.x, is executed as PHP by the web server, resulting in remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pluck CMSto a version that resolves this vulnerability.Fixed in 4.7.21 - Configuration
In data/inc/files.php, extend the fixed blacklist of dangerous extensions to include '.php8' alongside the existing entries like '.php','.php3','.php4','.php5','.php6','.php7','.phtml', etc. so that filenames ending in '.php8' are blocked.
Pluck CMS file-management upload blacklist data/inc/files.php (filename blacklist) = Add missing '.php8' to blacklist entries