FuseWP <= 1.1.24.2 - Cross-Site Request Forgery to Sync Rule Status Toggle
medium
The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24.2. This is due to missing nonce verification on the toggle_sync_status() function. This makes it possible for unauthenticated attackers to toggle the status of sync rules (enable/disable) via a forge...
- CVSS:
- 4.3
- Affected:
- up to 1.1.24.2
- Fixed in:
- 1.1.25.2
- Disclosed:
- Jul 28, 2026
CVE-2026-5582 on NVD →
FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) <= 1.1.23.0 - Missing Authorization to Authenticated (Subscriber+) Sync Rule Creation
medium
The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_changes() function in all versions up to, and including, 1.1.23.0. This makes it...
- CVSS:
- 4.3
- Affected:
- up to 1.1.23.0
- Fixed in:
- 1.1.23.1
- Disclosed:
- Oct 30, 2025
CVE-2025-11975 on NVD →
FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) <= 1.1.23.0 - Cross-Site Request Forgery to Sync Rule Creation
medium
The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.23.0. This is due to missing or incorrect nonce validation on the save_changes function. Thi...
- CVSS:
- 4.3
- Affected:
- up to 1.1.23.0
- Fixed in:
- 1.1.23.1
- Disclosed:
- Oct 24, 2025
CVE-2025-11976 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database