CVE-2024-6244
pz-frontend-manager < 1.0.6 - CSRF change user profile picture
- Published
- Jul 22, 2024
- Updated
- Mar 19, 2025
- Assigning CNA
- WPScan
- Evidence observed
- Apr 9, 2025
pz-frontend-manager < 1.0.6 - CSRF change user profile picture
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HLow · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
pz-frontend-manager < 1.0.6 - CSRF Profile Picture Exploit
Vuln Seeker Cybersecurity Team · php · Apr 9, 2025
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.