Description
The WP Fusion Lite WordPress plugin before 3.48.0 does not perform a capability check on two of its admin AJAX handlers, allowing any authenticated subscriber to read other users' email addresses and to trigger a cross-user CRM re-sync.
Published: 2026-10-01
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure and Unauthorized Data Manipulation
Action: Immediate Patch
AI Analysis

Impact

The WP Fusion Lite plugin before version 3.48.0 fails to perform a capability check on two admin AJAX handlers, allowing any authenticated subscriber to read other users’ email addresses and to trigger a cross‑user CRM re‑sync. This missing authorization check enables information disclosure and unauthorized manipulation of CRM data across user accounts, matching the CWE‑284 weakness of improper access control.

Affected Systems

All WordPress installations running WP Fusion Lite older than version 3.48.0 are vulnerable. Sites that have the plugin installed at any affected version may expose user email addresses and permit subscribers to initiate CRM re‑sync actions that impact other users.

Risk and Exploitability

The vulnerability can be exploited by any authenticated user with the subscriber role, requiring no higher privileges. The lack of a published CVSS or EPSS score does not reduce the seriousness; the attacker can retrieve sensitive user data and disrupt cross‑user data integrity. The attack vector is via the plugin’s AJAX API, limited to authenticated web application clients.

Generated by OpenCVE AI on October 1, 2026 at 08:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Fusion Lite to version 3.48.0 or later
  • Disable or restrict the vulnerable AJAX handlers to prevent unauthorized access
  • Monitor user activity and audit logs for anomalous CRM sync attempts

Generated by OpenCVE AI on October 1, 2026 at 08:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 01 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Fusion Lite WordPress plugin before 3.48.0 does not perform a capability check on two of its admin AJAX handlers, allowing any authenticated subscriber to read other users' email addresses and to trigger a cross-user CRM re-sync.
Title WP Fusion Lite < 3.48.0 - Subscriber+ User Email Disclosure and Cross-User CRM Data Deletion
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-01T10:45:49.067Z

Reserved: 2026-09-14T13:39:02.481Z

Link: CVE-2026-90972

cve-icon Vulnrichment

Updated: 2026-10-01T10:43:22.441Z

cve-icon NVD

Status : Received

Published: 2026-10-01T06:17:14.700

Modified: 2026-10-01T11:17:29.570

Link: CVE-2026-90972

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T08:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control