ludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /admin/install-theme/ endpoints. The application does not implement anti-CSRF tokens or other request origin validation mechanisms for these administrative actions. An attacker can induce an authenticated administrator to visit a malicious page that silently submits crafted requests, resulting in unauthorized plugin uninstallation or theme installation. This may lead to loss of functionality, execution of untrusted code via malicious themes, and compromise of system integrity.
| Link | Resource |
|---|---|
| https://github.com/bludit/bludit/issues/1577 | Exploit Issue Tracking |
| https://www.vulncheck.com/advisories/bludit-csrf-in-plugin-and-theme-management-endpoints | Third Party Advisory |
26 Feb 2026, 03:03
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Bludit bludit
Bludit |
|
| References | () https://github.com/bludit/bludit/issues/1577 - Exploit, Issue Tracking | |
| References | () https://www.vulncheck.com/advisories/bludit-csrf-in-plugin-and-theme-management-endpoints - Third Party Advisory | |
| CPE | cpe:2.3:a:bludit:bludit:3.16.1:*:*:*:*:*:*:* | |
| Summary |
|
23 Feb 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2026-02-23 22:16
Updated : 2026-02-26 03:03
NVD link : CVE-2026-27741
Mitre link : CVE-2026-27741
CVE.ORG link : CVE-2026-27741
JSON object : View
Cross-Site Request Forgery (CSRF)