MEDIUM
fusewp
CVE published 2026-07-30
CVE-2026-5582
The FuseWP plugin for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in versions up to and including 1.1.24.2. This is due to missing nonce verification on the toggle_sync_status() function. The vulnerability allows unauthenticated attackers to toggle the status of sync rules via a forged request, potentially impacting site integrity if an administrator is tricked into performing an actio [truncated]