plugin

Pz Frontend Manager Vulnerabilities

2 known security issues reported for the Pz Frontend Manager WordPress plugin. Most recent disclosed Apr 7, 2026.

2 medium

Running Pz Frontend Manager on your site? Check whether your installed version is affected.

Scan your site free

PZ Frontend Manager <= 1.0.6 - Missing Authorization to Arbitrary User Deletion via 'dataType' Parameter

medium

The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.6. The pzfm_user_request_action_callback() function, registered via the wp_ajax_pzfm_user_request_action action hook, lacks both capability checks and nonce verification. This function handles use...

CVSS:
5.3
Affected:
up to 1.0.6
Fix:
No patched version reported
Disclosed:
Apr 7, 2026

CVE-2026-3477 on NVD →

PZ Frontend Manager <= 1.0.5 - Cross-Site Request Forgery to Profile Picture Update

medium

The PZ Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the pzfm_upload_avatar_callback() function. This makes it possible for unauthenticated attackers to update profile pictures via a...

CVSS:
4.3
Affected:
up to 1.0.5
Fixed in:
1.0.6
Disclosed:
Jul 1, 2024

CVE-2024-6244 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database