MEDIUM
projectzealous01
CVE published 2026-04-08
CVE-2026-3477
The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.6. This vulnerability allows authenticated attackers, with Subscriber-level access and above, to delete arbitrary WordPress users, including administrators, by sending a crafted request to the AJAX endpoint. The vulnerability exists due to the pzfm_user_request_action_callback() func [truncated]