PatchSiren

projectzealous01 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM projectzealous01 CVE published 2026-04-08

CVE-2026-3477

The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.6. This vulnerability allows authenticated attackers, with Subscriber-level access and above, to delete arbitrary WordPress users, including administrators, by sending a crafted request to the AJAX endpoint. The vulnerability exists due to the pzfm_user_request_action_callback() func [truncated]