PT-2026-24402 · WordPress+1 · Massiveadmin+1

Dxleryt

·

Published

2026-03-10

·

Updated

2026-03-10

·

CVE-2026-28495

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GetSimple CMS versions 3.3.22 massiveAdmin plugin version 6.0.3
Description GetSimple CMS, when used with the massiveAdmin plugin version 6.0.3, allows an authenticated administrator to overwrite the gsconfig.php configuration file with arbitrary PHP code through the gsconfig editor module. The form lacks Cross-Site Request Forgery (CSRF) protection, enabling a remote unauthenticated attacker to exploit this through CSRF against a logged-in administrator, potentially leading to Remote Code Execution (RCE) on the web server. This can be triggered by a malicious email containing an embedded form, resulting in a full server compromise.
Recommendations For GetSimple CMS version 3.3.22 and massiveAdmin plugin version 6.0.3, ensure proper CSRF protection is implemented for the gsconfig editor module to prevent unauthorized modification of the gsconfig.php file.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-28495
GHSA-92WV-Q2JP-QG88

Affected Products

Getsimple Cms
Massiveadmin