CVE-2026-90974 - WP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings Update
CVE ID :CVE-2026-90974
Published : Oct. 1, 2026, 6:17 a.m. | 56 minutes ago
Description :The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker-chosen host.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 1, 2026, 6:17 a.m. | 56 minutes ago
Description :The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker-chosen host.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...