CVE Explorer
CVE-2026-3477
The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.6. The pzfm_user_request_action_callback() function, registered via the wp_ajax_pzfm_user_request_action action hook, lacks both capability checks and nonce verification. This function handles user activation, deactivation, and deletion operations. When the 'dataType' parameter is set to 'delete', the function calls wp_delete_user() on all provided user IDs without verifyin
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"PZ Frontend Manager","vendor":"projectzealous01","versions":[{"lessThanOrEqual":"1.0.6","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:af9da2ea642db559215608fe448d7f1ce760bdd6c7b1c38c663c83dcc93fce2c · sha256:e1a252b4c6c7be28… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:af9da2ea642db559215608fe448d7f1ce760bdd6c7b1c38c663c83dcc93fce2c · sha256:e1a252b4c6c7be28… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-862","description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:af9da2ea642db559215608fe448d7f1ce760bdd6c7b1c38c663c83dcc93fce2c · sha256:e1a252b4c6c7be28… · /containers/cna/problemTypes/0/descriptions/0
Source references
7 source assertions{"url":"https://plugins.trac.wordpress.org/browser/pz-frontend-manager/tags/1.0.6/admin/includes/ajax-hooks.php#L290"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:af9da2ea642db559215608fe448d7f1ce760bdd6c7b1c38c663c83dcc93fce2c · sha256:e1a252b4c6c7be28… · /containers/cna/references/6
{"url":"https://plugins.trac.wordpress.org/browser/pz-frontend-manager/tags/1.0.6/admin/includes/ajax-hooks.php#L292"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:af9da2ea642db559215608fe448d7f1ce760bdd6c7b1c38c663c83dcc93fce2c · sha256:e1a252b4c6c7be28… · /containers/cna/references/4
{"url":"https://plugins.trac.wordpress.org/browser/pz-frontend-manager/tags/1.0.6/admin/includes/ajax-hooks.php#L331"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:af9da2ea642db559215608fe448d7f1ce760bdd6c7b1c38c663c83dcc93fce2c · sha256:e1a252b4c6c7be28… · /containers/cna/references/2
{"url":"https://plugins.trac.wordpress.org/browser/pz-frontend-manager/trunk/admin/includes/ajax-hooks.php#L290"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:af9da2ea642db559215608fe448d7f1ce760bdd6c7b1c38c663c83dcc93fce2c · sha256:e1a252b4c6c7be28… · /containers/cna/references/5
{"url":"https://plugins.trac.wordpress.org/browser/pz-frontend-manager/trunk/admin/includes/ajax-hooks.php#L292"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:af9da2ea642db559215608fe448d7f1ce760bdd6c7b1c38c663c83dcc93fce2c · sha256:e1a252b4c6c7be28… · /containers/cna/references/3
{"url":"https://plugins.trac.wordpress.org/browser/pz-frontend-manager/trunk/admin/includes/ajax-hooks.php#L331"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:af9da2ea642db559215608fe448d7f1ce760bdd6c7b1c38c663c83dcc93fce2c · sha256:e1a252b4c6c7be28… · /containers/cna/references/1
{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/90d8e345-b549-493b-a84b-abe56ab42a04?source=cve"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:af9da2ea642db559215608fe448d7f1ce760bdd6c7b1c38c663c83dcc93fce2c · sha256:e1a252b4c6c7be28… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.