CVE-2024-6244 EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 3.2% (pctl 88)
Patch early
A public exploit exists.
Description
The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 3.18% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2024-07-22 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| projectzealous | pz frontend manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF) | 2025-04-09 |
References
→ the Explorer · watch your stack · NVD