CVE-2026-27741
Bludit <= 3.16.1 CSRF in Plugin and Theme Management Endpoints
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
Bludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /admin/install-theme/ endpoints. The application does not implement anti-CSRF tokens or other request origin validation mechanisms for these administrative actions. An attacker can induce an authenticated administrator to visit a malicious page that silently submits crafted requests, resulting in unauthorized plugin uninstallation or theme installation. This may lead to loss of functionality, execution of untrusted code via malicious themes, and compromise of system integrity.
| CWE | CWE-352 |
| Vendor | bludit |
| Product | bludit |
| Published | Feb 23, 2026 |
| Last Updated | Mar 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for bludit bludit
Be the first to know when new medium vulnerabilities affecting bludit bludit are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Affected Versions
Bludit / Bludit
0 โค 3.16.1
References
Credits
Ryan Chan (@RyanC34) Beatriz Fresno Naumova