Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 01 Oct 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Thu, 01 Oct 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-285 |
Thu, 01 Oct 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker-chosen host. | |
| Title | WP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings Update | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-01T10:45:48.928Z
Reserved: 2026-09-14T13:39:16.489Z
Link: CVE-2026-90974
Updated: 2026-10-01T10:43:13.092Z
Status : Deferred
Published: 2026-10-01T06:17:15.080
Modified: 2026-10-01T13:11:52.923
Link: CVE-2026-90974
No data.
OpenCVE Enrichment
Updated: 2026-10-01T07:45:04Z