vendor:
PZ Frontend Manager
by:
Vuln Seeker Cybersecurity Team
6.1
CVSS
HIGH
Cross Site Request Forgery (CSRF)
352
CWE
Product Name: PZ Frontend Manager
Affected Version From: 1.0.0
Affected Version To: 1.0.5
Patch Exists: NO
Related CWE: CVE-2024-XXXX (To be assigned)
CPE: a:wordpress:pz_frontend_manager:1.0.5
Platforms Tested: Firefox
2024
PZ Frontend Manager WordPress Plugin 1.0.5 – Cross Site Request Forgery (CSRF)
The PZ Frontend Manager WordPress Plugin version 1.0.5 and below is vulnerable to Cross Site Request Forgery (CSRF) attacks due to lack of CSRF checks in certain areas. This could allow malicious actors to manipulate logged in users into executing unintended actions.
Mitigation:
To mitigate this vulnerability, it is recommended to implement proper CSRF tokens and checks in the plugin code to validate user actions.