Bludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /admin/install-theme/ endpoints. The application does not implement anti-CSRF tokens or other request origin validation mechanisms for these administrative actions. An attacker can induce an authenticated administrator to visit a malicious page that silently submits crafted requests, resulting in unauthorized plugin uninstallation or theme installation. This may lead to loss of functionality, execution of untrusted code via malicious themes, and compromise of system integrity.
References
| Link | Resource |
|---|---|
| https://github.com/bludit/bludit/issues/1577 | Exploit Issue Tracking |
| https://www.vulncheck.com/advisories/bludit-csrf-in-plugin-and-theme-management-endpoints | Third Party Advisory |
Configurations
History
26 Feb 2026, 03:03
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CPE | cpe:2.3:a:bludit:bludit:3.16.1:*:*:*:*:*:*:* | |
| References | () https://github.com/bludit/bludit/issues/1577 - Exploit, Issue Tracking | |
| References | () https://www.vulncheck.com/advisories/bludit-csrf-in-plugin-and-theme-management-endpoints - Third Party Advisory | |
| First Time |
Bludit
Bludit bludit |
23 Feb 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-23 22:16
Updated : 2026-02-26 03:03
NVD link : CVE-2026-27741
Mitre link : CVE-2026-27741
CVE.ORG link : CVE-2026-27741
JSON object : View
Products Affected
bludit
- bludit
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
