CVE-2023-39310
The Fusion Builder plugin for WordPress contained an access control flaw in versions prior to 3.11.2 that allowed unauthenticated or low-privileged users to perform actions restricted to higher-privilege accounts. The issue stemmed from insufficient authorization checks in a particular function that failed to properly validate user permissions before executing sensitive operations. This vulnerability was discovered by Rafie Muhammad and has been patched in version 3.11.2 and later.
Based on public CVE data (MITRE/NVD).