CVE-2026-90974: Unknown Wp Fusion Lite

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker-chosen host.

Affected products

  • Unknown Wp Fusion Lite: from 3.37.14, before 3.48.0 (fixed in 3.48.0)

Published 2026-10-01. Last modified 2026-10-01.