๐Ÿ” CVE Alert

CVE-2026-90972

UNKNOWN 0.0

WP Fusion Lite < 3.48.0 - Subscriber+ User Email Disclosure and Cross-User CRM Data Deletion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The WP Fusion Lite WordPress plugin before 3.48.0 does not perform a capability check on two of its admin AJAX handlers, allowing any authenticated subscriber to read other users' email addresses and to trigger a cross-user CRM re-sync.

Vendor unknown
Product wp fusion lite
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wp fusion lite

Be the first to know when new unknown vulnerabilities affecting unknown wp fusion lite are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WP Fusion Lite
0 < 3.48.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/04d14406-c460-407c-836f-a9b5ed12be95/

Credits

Artus KG WPScan