CVE-2026-90972

The WP Fusion Lite WordPress plugin before 3.48.0 does not perform a capability check on two of its admin AJAX handlers, allowing any authenticated subscriber to read other users' email addresses and to trigger a cross-user CRM re-sync.

  • Published Oct 1, 2026
  • CVSS 5.4 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-90972 at the National Vulnerability Database