Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Pluck-CMS-Pluck-4.7.16-Theme-Upload-Remote-Code-Execution-Authenticated--POC — Exploit script for CVE-2022-26965; authenticated theme upload remote code execution in PluckCMS 4.7.16, delivering a webshell via shell.tar. | Kitploit
Tools/GitHubGitHub/shikari00007/pluck-cms-pluck-4.7.16-theme-upload-remote-code-execution-authenticated--poc
Vulnerability AnalysisExploitationWeb Application Exploitation
GitHubshikari00007/pluck-cms-pluck-4.7.16-theme-upload-remote-code-execution-authenticated--poc

Pluck-CMS-Pluck-4.7.16-Theme-Upload-Remote-Code-Execution-Authenticated--POC

Exploit script for CVE-2022-26965; authenticated theme upload remote code execution in PluckCMS 4.7.16, delivering a webshell via shell.tar.

View Repository
6224 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Pluck-CMS-Pluck-4.7.16-Theme-Upload-Remote-Code-Execution-Authenticated-POC

  • Exploit Author: Ashish Koli (Shikari)
  • Vendor Homepage: https://github.com/pluck-cms/pluck
  • Version: 4.7.16
  • CVE: CVE-2022-26965
  • About this:
  • This script uploads shell.tar to the PluckCMS. An application will untar the
  • package which allows us to access Webshell.
  • Usage : python3 exploit.py
  • Example: python3 exploit.py 127.0.0.1 80 admin /pluck
  • POC Exploit: https://youtu.be/vWZITp_FTTc
Download Tool