Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-90972 | 1 Wordpress-extensions | 1 Wp Fusion Lite | 2026-10-01 | 5.4 Medium |
| The WP Fusion Lite WordPress plugin before 3.48.0 does not perform a capability check on two of its admin AJAX handlers, allowing any authenticated subscriber to read other users' email addresses and to trigger a cross-user CRM re-sync. | ||||
| CVE-2026-90974 | 1 Wordpress-extensions | 1 Wp Fusion Lite | 2026-10-01 | 6.5 Medium |
| The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker-chosen host. | ||||
Page 1 of 1.