peter bassill · operator
$ cve CVE-2024-6244 JSON

CVE-2024-6244 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 3.2% (pctl 88)

Patch early

A public exploit exists.

Description

The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS3.18% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2024-07-22
Last modified2026-06-17

Affected (1)

VendorProduct
projectzealouspz frontend manager

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD