Description
The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker-chosen host.
Published: 2026-10-01
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized data exfiltration via installed plugin configuration changes
Action: Immediate Patch
AI Analysis

Impact

WP Fusion Lite before 3.48.0 does not require authentication on a settings handler that runs during admin initialization. Unauthenticated users can overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker‑chosen host. The vulnerability allows an attacker to alter configuration settings without authorization, leading to confidentiality loss by redirecting sensitive user data to an external server. The weakness corresponds to CWE‑285 (Improper Authorization) and potentially CWE‑200 (Exposure of Sensitive Information to an Unauthorized Actor).

Affected Systems

The WordPress plugin WP Fusion Lite versions 3.37.14 through 3.47.14 are affected. Any installation of the plugin before version 3.48.0 that uses the CRM integration feature and runs during admin initialization is vulnerable.

Risk and Exploitability

The vulnerability is exploitable from the web without any credentials, making the attack vector unauthenticated remote access. The EPSS score is not available, and the issue is not listed in CISA's KEV catalog. While the likelihood depends on the presence of the vulnerable plugin on a target site, the impact is severe due to potential complete exposure of synced user data. The risk is therefore high, especially for sites that rely on the CRM integration for critical data synchronization.

Generated by OpenCVE AI on October 1, 2026 at 07:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Fusion Lite to version 3.48.0 or later.
  • If an upgrade cannot be performed immediately, consider disabling or removing the plugin to prevent the settings handler from executing during admin initialization.
  • Monitor outgoing network traffic for unexpected connections to external CRM endpoints, and audit CRM integration settings for unauthorized changes.

Generated by OpenCVE AI on October 1, 2026 at 07:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Thu, 01 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker-chosen host.
Title WP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings Update
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-01T06:00:25.279Z

Reserved: 2026-09-14T13:39:16.489Z

Link: CVE-2026-90974

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T06:17:15.080

Modified: 2026-10-01T06:17:15.080

Link: CVE-2026-90974

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T07:45:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-285

    Improper Authorization