CVE WATCH / VULNERABILITY DETAIL

CVE-2026-90974

MEDIUMCVSS 6.5NVD feed

Published 1 October 2026 · tracked since 1 October 2026

Description

The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker-ch

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-90974 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-90974

MEDIUMCVSS 6.5NVD feed

Published 1 October 2026 · tracked since 1 October 2026

Description

The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker-ch

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]