An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files.Referenceshttps://github.com/pluck-cms/pluck/issues/83https://github.com/pluck-cms/pluck/issues/91