๐Ÿ” CVE Alert

CVE-2026-27741

MEDIUM 4.3

Bludit <= 3.16.1 CSRF in Plugin and Theme Management Endpoints

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Bludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /admin/install-theme/ endpoints. The application does not implement anti-CSRF tokens or other request origin validation mechanisms for these administrative actions. An attacker can induce an authenticated administrator to visit a malicious page that silently submits crafted requests, resulting in unauthorized plugin uninstallation or theme installation. This may lead to loss of functionality, execution of untrusted code via malicious themes, and compromise of system integrity.

CWE CWE-352
Vendor bludit
Product bludit
Published Feb 23, 2026
Last Updated Mar 5, 2026
Stay Ahead of the Next One

Get instant alerts for bludit bludit

Be the first to know when new medium vulnerabilities affecting bludit bludit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

Bludit / Bludit
0 โ‰ค 3.16.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/bludit/bludit/issues/1577 vulncheck.com: https://www.vulncheck.com/advisories/bludit-csrf-in-plugin-and-theme-management-endpoints

Credits

Ryan Chan (@RyanC34) Beatriz Fresno Naumova