What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lite: from n/a through <= 3.41.24.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lite: from n/a through <= 3.41.24.
Explanation of Vulnerability in Simple Terms
WP Fusion Lite versions up to 3.41.24 contain a code injection vulnerability that allows authenticated users with low privileges to execute arbitrary PHP code on the site. The vulnerability affects the plugin's handling of user input and can impact confidentiality, integrity, and availability of the entire WordPress installation. Site administrators should update immediately to a patched version.
What an attacker can do
Run arbitrary PHP code on the site with full access to the WordPress database and files.
Potential impact on your site
Complete compromise of the WordPress site, including data theft, malware injection, and site takeover.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities