PZ Frontend Manager <= 1.0.6 - Missing Authorization to Arbitrary User Deletion via 'dataType' Parameter
medium
The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.6. The pzfm_user_request_action_callback() function, registered via the wp_ajax_pzfm_user_request_action action hook, lacks both capability checks and nonce verification. This function handles use...
- CVSS:
- 5.3
- Affected:
- up to 1.0.6
- Fix:
- No patched version reported
- Disclosed:
- Apr 7, 2026
CVE-2026-3477 on NVD →
PZ Frontend Manager <= 1.0.5 - Cross-Site Request Forgery to Profile Picture Update
medium
The PZ Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the pzfm_upload_avatar_callback() function. This makes it possible for unauthenticated attackers to update profile pictures via a...
- CVSS:
- 4.3
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.6
- Disclosed:
- Jul 1, 2024
CVE-2024-6244 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database