Impact
The WP Fusion Lite plugin before version 3.48.0 fails to perform a capability check on two admin AJAX handlers, allowing any authenticated subscriber to read other users’ email addresses and to trigger a cross‑user CRM re‑sync. This missing authorization check enables information disclosure and unauthorized manipulation of CRM data across user accounts, matching the CWE‑284 weakness of improper access control.
Affected Systems
All WordPress installations running WP Fusion Lite older than version 3.48.0 are vulnerable. Sites that have the plugin installed at any affected version may expose user email addresses and permit subscribers to initiate CRM re‑sync actions that impact other users.
Risk and Exploitability
The vulnerability can be exploited by any authenticated user with the subscriber role, requiring no higher privileges. The lack of a published CVSS or EPSS score does not reduce the seriousness; the attacker can retrieve sensitive user data and disrupt cross‑user data integrity. The attack vector is via the plugin’s AJAX API, limited to authenticated web application clients.
OpenCVE Enrichment