{"error":0,"message":null,"data":{"name":"Hustle &#8211; Email Marketing, Lead Generation, Optins, Popups","plugin":"wordpress-popup","link":"https:\/\/wordpress.org\/plugins\/wordpress-popup\/","latest":"1788178260","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"7e7438520bb3ec6685cd34965800ecd86d16d517ad15f9c4b371b9c3d2534826","name":"Hustle &#8211; Email Marketing, Lead Generation, Optins, Popups [wordpress-popup] <= 6.0.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.0.5","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-18576","name":"CVE-2018-18576","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-18576","description":"[en] The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views\/admin\/dashboard\/ URI.","date":"2020-03-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}]}},{"uuid":"a07d488dcfbd68a9d271c3e612ddca1a939429ddbebb436fb741b38a39f70236","name":"Hustle &#8211; Email Marketing, Lead Generation, Optins, Popups [wordpress-popup] < 6.0.8.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.0.8.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-11872","name":"CVE-2019-11872","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-11872","description":"[en] The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation grants an attacker with a right to execute malicious code on the administrator's computer through Excel functions as the plugin does not sanitize the user's input and allows insertion of any text.","date":"2019-05-29"},{"id":"285fd7667bd0e76002d6c463edb7dd81effab9ce","name":"WordPress Hustle \u2013 Pop-Ups, Slide-ins and Email Opt-ins plugin <= 6.0.7 - Unauthenticated CSV Injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordpress-popup\/vulnerability\/wordpress-hustle-pop-ups-slide-ins-and-email-opt-ins-plugin-6-0-7-unauthenticated-csv-injection-vulnerability","description":"Unauthenticated CSV Injection vulnerability found by Mark Parfeniuk in WordPress Hustle \u2013 Pop-Ups, Slide-ins and Email Opt-ins plugin (versions <= 6.0.7).","date":"2019-06-11"},{"id":"72f8e72a18d8a4c0469220053e2e1b92a8813c47","name":"Hustle <= 6.0.7 - Unauthenticated CSV Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordpress-popup\/hustle-607-unauthenticated-csv-injection","description":"The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation grants an attacker with a right to execute malicious code on the administrator's computer through Excel functions as the plugin does not sanitize the user's input and allows insertion of any text.","date":"2019-05-24"},{"id":"b9502301-3cc4-4ab0-a223-5bfdca33b0b9","name":"Hustle &lt;= 6.0.7 - Unauthenticated CSV Injection","link":"https:\/\/wpscan.com\/vulnerability\/b9502301-3cc4-4ab0-a223-5bfdca33b0b9","description":"The Hustle &ndash; Email Marketing, Lead Generation, Optins, Popups WordPress plugin was affected by an Unauthenticated CSV Injection security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-1236","name":"Improper Neutralization of Formula Elements in a CSV File","description":"The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product."}]}},{"uuid":"97b85d7b7220f921caca8fa3397492492f9bc57ac4652f775cf28df5ddb85867","name":"Hustle &#8211; Email Marketing, Lead Generation, Optins, Popups [wordpress-popup] < 7.6.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.6.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"710833c1de6261a8b88a637b2696f8174266738d","name":"Hustle <= 7.6.4 = Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordpress-popup\/hustle-764-authenticated-administrator-stored-cross-site-scripting","description":"The Hustle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 7.6.4  due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2023-04-06"}],"impact":[]},{"uuid":"038eeba04c89ff3fd3edb321ef5d61b712be78f612d31295b4d37064d79c2f24","name":"Hustle &#8211; Email Marketing, Lead Generation, Optins, Popups [wordpress-popup] < 7.8.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.8.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-0368","name":"CVE-2024-0368","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-0368","description":"[en] The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via hardcoded API Keys. This makes it possible for unauthenticated attackers to extract sensitive data including PII.","date":"2024-03-13"},{"id":"aabdb21ce5a0c7e0fef1e83f3edbe2ea33ba47ed","name":"Hustle <= 7.8.3 - Sensitive Information Exposure via Exposed Hubspot API Keys","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordpress-popup\/hustle-783-sensitive-information-exposure-via-exposed-hubspot-api-keys","description":"The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via hardcoded API Keys. This makes it possible for unauthenticated attackers to extract sensitive data including PII.","date":"2024-03-12"},{"id":"19c8644922a867c2c62a32a54142f721ca58cf1d","name":"WordPress  Hustle Plugin    <= 7.8.3 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordpress-popup\/vulnerability\/wordpress-hustle-plugin-7-8-3-sensitive-information-exposure-via-exposed-hubspot-api-keys-vulnerability","description":"Update the WordPress Hustle plugin to the latest available version (at least 7.8.4).\nSean Murphy discovered and reported this Sensitive Data Exposure vulnerability in WordPress Hustle Plugin.  This vulnerability has been fixed in version 7.8.4.\nHave additional information or questions about this entry? Get in touch.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"h","i":"n","a":"n","score":"8.6","severity":"h","exploitable":"3.9","impact":"4.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:N\/A:N","score":"8.6","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"4.0"},"cwe":[{"cwe":"CWE-522","name":"Insufficiently Protected Credentials","description":"The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and\/or retrieval."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f040af0ef6ac4c07310cc2152c35739adc926deb3aeeb2d064f93a5cd9f9ff2f","name":"Hustle &#8211; Email Marketing, Lead Generation, Optins, Popups [wordpress-popup] < 7.8.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.8.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8492","name":"Hustle < 7.8.5 - Admin+ Stored XSS","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8492","description":"The Hustle  WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed","date":"0000-00-00"},{"id":"a70a8c3705c99898065bd427f3cd9f13d0a7b059","name":"Hustle <= 7.8.4 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordpress-popup\/hustle-784-authenticated-administrator-stored-cross-site-scripting","description":"The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-07-29"},{"id":"EUVD-2025-15259","name":"EUVD-2025-15259","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-15259","description":"The Hustle  WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed","date":"2025-05-15"},{"id":"08c2ccd199cf920cb6856b4d847a4a65a62ae776","name":"WordPress Hustle Plugin < 7.8.5 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordpress-popup\/vulnerability\/wordpress-hustle-plugin-7-8-5-admin-stored-xss-vulnerability","description":"<p>WordPress Hustle Plugin < 7.8.5 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Hustle<\/p><p>Fixed in version 7.8.5 <\/p><p>Affected Version < 7.8.5<\/p><p>CVE: CVE-2024-8492<\/p>","date":"2025-05-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"483423af46ad501b123de60b8a6036b24fc27f18d8aa046af56b2efe52b588d8","name":"Hustle &#8211; Email Marketing, Lead Generation, Optins, Popups [wordpress-popup] < 7.8.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.8.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10579","name":"CVE-2024-10579","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10579","description":"[en] The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the preview_module() function in all versions up to, and including, 7.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view unpublished forms.","date":"2024-11-26"},{"id":"7f814c02675049defefbed21fc3e118bf6c6a36e","name":"Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unpublished Form Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordpress-popup\/hustle-email-marketing-lead-generation-optins-popups-785-missing-authorization-to-unpublished-form-exposure","description":"The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the preview_module() function in all versions up to, and including, 7.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view unpublished forms.","date":"2024-11-25"},{"id":"742e4ed6600751df5fcb40f24c392823e0a8b9a8","name":"WordPress Hustle Plugin <= 7.8.5 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordpress-popup\/vulnerability\/wordpress-hustle-plugin-7-8-5-missing-authorization-to-unpublished-form-exposure-vulnerability","description":"<p>WordPress Hustle Plugin <= 7.8.5 is vulnerable to Broken Access Control<\/p><p>Software: Hustle<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wordpress-popup\/#developers<\/p><p>Affected Version <= 7.8.5<\/p><p>Fixed in version 7.8.6 <\/p>","date":"2024-11-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2b0e3c235eff442daca294451fb1e4b056282a93a04d656ec06fa79047b050d9","name":"Hustle &#8211; Email Marketing, Lead Generation, Optins, Popups [wordpress-popup] < 7.8.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.8.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10580","name":"CVE-2024-10580","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10580","description":"[en] The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form submissions due to a missing capability check on the submit_form() function in all versions up to, and including, 7.8.5. This makes it possible for unauthenticated attackers to submit unpublished forms.","date":"2024-11-27"},{"id":"41309073d128d778678d3c84fb6743b932f13c4a","name":"WordPress Hustle Plugin <= 7.8.5 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordpress-popup\/vulnerability\/wordpress-hustle-plugin-7-8-5-missing-authorization-to-unauthorized-form-submission-vulnerability","description":"<p>WordPress Hustle Plugin <= 7.8.5 is vulnerable to Broken Access Control<\/p><p>Software: Hustle<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wordpress-popup\/#developers<\/p><p>Affected Version <= 7.8.5<\/p><p>Fixed in version 7.8.6 <\/p>","date":"2024-11-26"},{"id":"8fd2ef875576d8b9b5e0c51a7a707769ef887f2d","name":"Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unauthorized Form Submission","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordpress-popup\/hustle-email-marketing-lead-generation-optins-popups-785-missing-authorization-to-unauthorized-form-submission","description":"The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form submissions due to a missing capability check on the submit_form() function in all versions up to, and including, 7.8.5. This makes it possible for unauthenticated attackers to submit unpublished forms.","date":"2024-11-26"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6f0793dd8acfd6df8a0597d94f4a818e488aec7be5b937cec68115e95df2f161","name":"Hustle &#8211; Email Marketing, Lead Generation, Optins, Popups [wordpress-popup] < 7.8.9.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.8.9.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-24998","name":"CVE-2026-24998","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-24998","description":"[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hustle wordpress-popup allows Retrieve Embedded Sensitive Data.This issue affects Hustle: from n\/a through <= 7.8.9.2.","date":"2026-02-03"},{"id":"d68a3c37ce1af0a9bbb4ae73e67529370e2dfc9c","name":"Hustle <= 7.8.9.2 - Unauthenticated Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordpress-popup\/hustle-7892-unauthenticated-information-exposure","description":"The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.9.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.","date":"2026-01-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-497","name":"Exposure of Sensitive System Information to an Unauthorized Control Sphere","description":"The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"abdfb9b3207382df799b704d7033907e660fdb19997d6fc414ad9df8ab433e79","name":"Hustle &#8211; Email Marketing, Lead Generation, Optins, Popups [wordpress-popup] < 7.8.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.8.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-2263","name":"Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups <= 7.8.10.2 - Missing Authorization to Unauthenticated Conversion Tracking Data Manipulation","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-2263","description":"The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hustle_module_converted' AJAX action in all versions up to, and including, 7.8.10.2. This makes it possible for unauthenticated attackers to forge conversion tracking events for any Hustle module, including draft modules that are never displayed to users, thereby manipulating marketing analytics and conversion statistics.","date":"0000-00-00"},{"id":"da0305ea18a1177ad3f977e25e8e22b8ed0af88f","name":"Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups <= 7.8.10.2 - Missing Authorization to Unauthenticated Conversion Tracking Data Manipulation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordpress-popup\/hustle-email-marketing-lead-generation-optins-popups-78102-missing-authorization-to-unauthenticated-conversion-tracking-data-manipulation","description":"The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hustle_module_converted' AJAX action in all versions up to, and including, 7.8.10.2. This makes it possible for unauthenticated attackers to forge conversion tracking events for any Hustle module, including draft modules that are never displayed to users, thereby manipulating marketing analytics and conversion statistics.","date":"2026-04-07"},{"id":"EUVD-2026-19988","name":"EUVD-2026-19988","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-19988","description":"The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hustle_module_converted' AJAX action in all versions up to, and including, 7.8.10.2. This makes it possible for unauthenticated attackers to forge conversion tracking events for any Hustle module, including draft modules that are never displayed to users, thereby manipulating marketing analytics and conversion statistics.","date":"2026-04-08"}],"impact":{"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":null,"impact":null}}},{"uuid":"91360ac51787a8aa6b7ddc0a3a191d275f6e7e1b3fd2e2f4da0e3f91d76ee6e5","name":"Hustle &#8211; Email Marketing, Lead Generation, Optins, Popups [wordpress-popup] < 7.8.9.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.8.9.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-0911","name":"Hustle <= 7.8.9.2 - Authenticated (Subscriber+) Arbitrary File Upoload via Module Import","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-0911","description":"The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the action_import_module() function in all versions up to, and including, 7.8.9.2. This makes it possible for authenticated attackers, with a lower-privileged role (e.g., Subscriber-level access and above), to upload arbitrary files on the affected site's server which may make remote code execution possible. Successful exploitation requires an admin to grant Hustle module permissions (or module edit access) to the low-privileged user so they can access the Hustle admin page and obtain the required nonce.","date":"0000-00-00"},{"id":"EUVD-2026-4543","name":"EUVD-2026-4543","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-4543","description":"The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the action_import_module() function in all versions up to, and including, 7.8.9.2. This makes it possible for authenticated attackers, with a lower-privileged role (e.g., Subscriber-level access and above), to upload arbitrary files on the affected site's server which may make remote code execution possible. Successful exploitation requires an admin to grant Hustle module permissions (or module edit access) to the low-privileged user so they can access the Hustle admin page and obtain the required nonce.","date":"2026-01-24"},{"id":"7f4887f0eb8506d13c5cf639f954d878cfd71c17","name":"Hustle <= 7.8.9.2 - Authenticated (Subscriber+) Arbitrary File Upoload via Module Import","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordpress-popup\/hustle-7892-authenticated-subscriber-arbitrary-file-upoload-via-module-import","description":"The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the action_import_module() function in all versions up to, and including, 7.8.9.2. This makes it possible for authenticated attackers, with a lower-privileged role (e.g., Subscriber-level access and above), to upload arbitrary files on the affected site's server which may make remote code execution possible. Successful exploitation requires an admin to grant Hustle module permissions (or module edit access) to the low-privileged user so they can access the Hustle admin page and obtain the required nonce.","date":"2026-01-23"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.5","severity":"high","av":"network","ac":"high","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":null,"impact":null},"epss":"0.001"}},{"uuid":"418f27387b9f81e911e1cefb443d87e4d7c5babb2c8dfee249bb391c3e387452","name":"Hustle &#8211; Email Marketing, Lead Generation, Optins, Popups [wordpress-popup] < 7.8.10.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.8.10.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-25431","name":"CVE-2026-25431","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-25431","description":"[en] Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Hustle: through 7.8.10.1.","date":"2026-05-12"},{"id":"a5accf9212c629751f551a48eb35d0424c245b1b","name":"Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups <= 7.8.10.1 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordpress-popup\/hustle-email-marketing-lead-generation-optins-popups-78101-missing-authorization","description":"The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.8.10.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-05-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c11bddac48cc6fe595c24aa0806f332650b216b25a9c9a7d11540a347ee34c1d","name":"Hustle &#8211; Email Marketing, Lead Generation, Optins, Popups [wordpress-popup] < 7.8.14.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.8.14.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-80440","name":"CVE-2026-80440","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-80440","description":"[en] The Hustle WordPress plugin before 7.8.14.2 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into the message it returns after submission, because the guard it applies can be defeated by nesting, allowing unauthenticated users to run any shortcode registered on the site.","date":"2026-09-09"},{"id":"9ec142c3660cf19ea7295662791979aac2e678f9","name":"Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups < 7.8.14.2 - Unauthenticated Arbitrary Shortcode Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordpress-popup\/hustle-email-marketing-lead-generation-optins-popups-78142-unauthenticated-arbitrary-shortcode-execution","description":"The Hustle \u2013 Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 7.8.14.2. This is due to use of strip_shortcodes on submitted field values, which can be bypassed by nesting brackets, instead of encoding square brackets to prevent shortcode formation entirely. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes registered on the site by submitting bracket-nested shortcode payloads in form fields that are reflected in the post-submission success message.","date":"2026-05-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-74","name":"Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')","description":"The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789642283"}