Description
The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_changes() function in all versions up to, and including, 1.1.23.0. This makes it possible for unauthenticated attackers to add and edit sync rules.
Problem types
Product status
* (semver)
Timeline
| 2025-10-20: | Vendor Notified |
| 2025-10-30: | Disclosed |
Credits
Jonas Benjamin Friedli
References
www.wordfence.com/...-926f-497f-b9f2-b0a67cd09adf?source=cve
plugins.trac.wordpress.org/...dmin/SettingsPage/SyncPage.php