WordPress Plugin Vulnerabilities

WP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings Update

Description

The plugin does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker-chosen host.

Proof of Concept

Affects Plugins

Fixed in 3.48.0

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Naoki Kawahigashi
Submitter
Naoki Kawahigashi
Verified
Yes

Timeline

Publicly Published
2026-09-29 (about 2 days ago)
Added
2026-09-29 (about 1 day ago)
Last Updated
2026-09-29 (about 1 day ago)

Other