PT-2026-21568 · Bludit · Bludit
Ryan Chan
·
Published
2026-02-23
·
Updated
2026-02-24
·
CVE-2026-27741
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Bludit version 3.16.1
Description
The application lacks anti-CSRF tokens or request origin validation for administrative actions. An attacker can trick an authenticated administrator into visiting a malicious page, which silently submits crafted requests. This can lead to unauthorized plugin uninstallation via the
/admin/uninstall-plugin/ endpoint or theme installation via the /admin/install-theme/ endpoint. Successful exploitation may result in loss of functionality, execution of untrusted code through malicious themes, and compromise of system integrity.Recommendations
Apply updates to address the issue in Bludit version 3.16.1.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bludit