PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5582 fusewp CVE debrief

The FuseWP plugin for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in versions up to and including 1.1.24.2. This is due to missing nonce verification on the toggle_sync_status() function. The vulnerability allows unauthenticated attackers to toggle the status of sync rules via a forged request, potentially impacting site integrity if an administrator is tricked into performing an action. This issue affects WordPress administrators and users of the FuseWP plugin, especially those with sync rules configured. Evidence from Wordfence and NVD indicates a CSRF vulnerability in FuseWP plugin versions up to 1.1.24.2. Limited details on affected scope and vendor remediation are available. Defenders should verify the integrity of sync rules and monitor for suspicious activity.

Vendor
fusewp
Product
FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-07-31
Advisory published
2026-07-30
Advisory updated
2026-07-31

Who should care

WordPress administrators and users of the FuseWP plugin, especially those with sync rules configured, should be aware of this vulnerability and take steps to protect their sites. This includes verifying and applying patches, monitoring for suspicious activity, and restricting access to sync rule management. Site owners should also review compensating controls and ensure that their security teams are informed about the potential impact on their environments.

Technical summary

The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24.2 due to missing nonce verification on the toggle_sync_status() function. This allows unauthenticated attackers to toggle the status of sync rules via a forged request, potentially impacting site integrity if an administrator is tricked into performing an action. The vulnerability has a CVSS score of 4.3 and a severity rating of MEDIUM. Site owners should review compensating controls and ensure that their security teams are informed about the potential impact on their environments. WordPress administrators and users of the FuseWP plugin should be aware of this vulnerability and take steps to protect their sites.

Defensive priority

Medium priority due to CSRF vulnerability allowing unauthenticated attackers to toggle sync rule status.

Recommended defensive actions

  • Verify and apply vendor patch for FuseWP plugin version 1.1.24.2 or earlier
  • Implement additional monitoring for suspicious sync rule status changes
  • Restrict access to sync rule management for authenticated users
  • Consider compensating controls for WordPress installations using FuseWP
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The FuseWP plugin for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in versions up to and including 1.1.24.2. This is due to missing nonce verification on the toggle_sync_status() function. Evidence from Wordfence and NVD indicates a CSRF vulnerability in FuseWP plugin versions up to 1.1.24.2. Limited details on affected scope and vendor remediation are available. Defenders should verify the integrity of sync rules and monitor for suspicious activity. The CVE record was published on 2026-07-30T12:19:03.080Z and has not been modified since then.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T12:19:03.080Z and has not been modified since then.