Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2024-6244
HistoryJul 22, 2024 - 6:00 a.m.

CVE-2024-6244 pz-frontend-manager < 1.0.6 - CSRF change user profile picture

2024-07-2206:00:06
WPScan
github.com
2
cve-2024-6244
pz-frontend-manager
csrf
change user profile picture
wordpress plugin
csrf checks
logged in users
unwanted actions

AI Score

7

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:wordpress_plugin:pz_frontend_manager:*:*:*:*:*:*:*:*"
    ],
    "vendor": "wordpress_plugin",
    "product": "pz_frontend_manager",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "1.0.6",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

7

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-6244