VYPR

PZ Frontend Manager

by WordPress

CVEs (2)

  • CVE-2024-6244HigJul 22, 2024
    risk 0.60cvss 8.8epss 0.03

    The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

  • CVE-2026-3477MedApr 8, 2026
    risk 0.34cvss 5.3epss 0.00

    The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.6. The pzfm_user_request_action_callback() function, registered via the wp_ajax_pzfm_user_request_action action hook, lacks both capability checks and…