PatchSiren

fusewp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM fusewp CVE published 2026-07-30

CVE-2026-5582

The FuseWP plugin for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in versions up to and including 1.1.24.2. This is due to missing nonce verification on the toggle_sync_status() function. The vulnerability allows unauthenticated attackers to toggle the status of sync rules via a forged request, potentially impacting site integrity if an administrator is tricked into performing an actio [truncated]