Impact
WP Fusion Lite before 3.48.0 does not require authentication on a settings handler that runs during admin initialization. Unauthenticated users can overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker‑chosen host. The vulnerability allows an attacker to alter configuration settings without authorization, leading to confidentiality loss by redirecting sensitive user data to an external server. The weakness corresponds to CWE‑285 (Improper Authorization) and potentially CWE‑200 (Exposure of Sensitive Information to an Unauthorized Actor).
Affected Systems
The WordPress plugin WP Fusion Lite versions 3.37.14 through 3.47.14 are affected. Any installation of the plugin before version 3.48.0 that uses the CRM integration feature and runs during admin initialization is vulnerable.
Risk and Exploitability
The vulnerability is exploitable from the web without any credentials, making the attack vector unauthenticated remote access. The EPSS score is not available, and the issue is not listed in CISA's KEV catalog. While the likelihood depends on the presence of the vulnerable plugin on a target site, the impact is severe due to potential complete exposure of synced user data. The risk is therefore high, especially for sites that rely on the CRM integration for critical data synchronization.
OpenCVE Enrichment