CVE-2026-90974
WP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings Update
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker-chosen host.
| Vendor | unknown |
| Product | wp fusion lite |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp fusion lite
Be the first to know when new unknown vulnerabilities affecting unknown wp fusion lite are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP Fusion Lite
3.37.14 < 3.48.0
References
Credits
Naoki Kawahigashi WPScan