PT-2026-66462 · WordPress · Fusewp
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FuseWP versions prior to 1.1.24.3
Description
The FuseWP plugin for WordPress contains a Cross-Site Request Forgery (CSRF) flaw, which occurs when a web application fails to verify that a request was intentionally initiated by the user. This issue is caused by missing nonce verification in the
toggle sync status() function. Unauthenticated attackers can exploit this by tricking a site administrator into clicking a malicious link, allowing the attacker to enable or disable sync rules via a forged request.Recommendations
Update the plugin to a version later than 1.1.24.2.
As a temporary workaround, restrict access to the
toggle sync status() function until the update is applied.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fusewp