Unrated severityNVD Advisory· Published Oct 1, 2026
CVE-2026-90972
CVE-2026-90972
Description
The WP Fusion Lite WordPress plugin before 3.48.0 does not perform a capability check on two of its admin AJAX handlers, allowing any authenticated subscriber to read other users' email addresses and to trigger a cross-user CRM re-sync.
Affected products
1- Range: <3.48.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.