CVE-2026-90972 - WP Fusion Lite < 3.48.0 - Subscriber+ User Email Disclosure and Cross-User CRM Data Deletion
CVE ID :CVE-2026-90972
Published : Oct. 1, 2026, 6:17 a.m. | 56 minutes ago
Description :The WP Fusion Lite WordPress plugin before 3.48.0 does not perform a capability check on two of its admin AJAX handlers, allowing any authenticated subscriber to read other users' email addresses and to trigger a cross-user CRM re-sync.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 1, 2026, 6:17 a.m. | 56 minutes ago
Description :The WP Fusion Lite WordPress plugin before 3.48.0 does not perform a capability check on two of its admin AJAX handlers, allowing any authenticated subscriber to read other users' email addresses and to trigger a cross-user CRM re-sync.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...