CVE-2026-90972: WP Fusion Lite < 3.48.0 - Subscriber+ User Email Disclosure and Cross-User CRM Data Deletion
Published Oct 1, 2026
·Updated
The WP Fusion Lite WordPress plugin before 3.48.0 does not perform a capability check on two of its admin AJAX handlers, allowing any authenticated subscriber to read other users' email addresses and to trigger a cross-user CRM re-sync.
Affected Software
1 affected component
WP Fusion WP Fusion Lite<3.48.0
Event History
Oct 1, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any authenticated WordPress user with the Subscriber role or higher can exploit the affected admin AJAX handlers. The issue does not require administrator-level permissions.
2
What information or actions are exposed?
An attacker can read other users' email addresses and trigger CRM re-synchronization for other users. The re-sync action can result in cross-user CRM data deletion.
3
Which versions are affected?
WP Fusion Lite versions before 3.48.0 are affected.