CVE-2026-90974: WP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings Update
The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker-chosen host.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP Fusion Liteto a version that resolves this vulnerability.Fixed in 3.48.0
Event History
Frequently Asked Questions
Which installations are affected?
WP Fusion Lite versions 3.37.14 through 3.47.14 are affected. The issue is fixed in version 3.48.0 and later.
Does an attacker need a WordPress account to exploit this?
No. The vulnerable settings handler does not require authentication, so unauthenticated users can overwrite the CRM integration endpoint and credentials.
What is the practical impact if exploitation succeeds?
An attacker can redirect the site's CRM integration to a host they control. Synced user data may then be delivered to that attacker-chosen host.
How can I determine whether my site may already be affected?
Review the configured CRM integration endpoint and credentials for unexpected changes, particularly values pointing to an unrecognized host. Also investigate whether synced user data was sent to an unauthorized destination.