Hustle – Email Marketing, Lead Generation, Optins, Popups
wordpress-popup · plugin
Known security vulnerabilities for Hustle – Email Marketing, Lead Generation, Optins, Popups. Find out in seconds which version runs on your site with WP Lens.
9 known vulnerabilities
7 exploitable without logging in · 2 with public exploit code · latest May 12, 2026
Listed on wordpress.org · latest 7.8.14.2 · last updated Aug 31, 2026 · 90K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- High 8.8
CVE-2019-11872unauthenticated · needs a click
The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a
- High 8.6
CVE-2024-0368unauthenticated≤ 7.8.3
Hustle <= 7.8.3 - Sensitive Information Exposure via Exposed Hubspot API Keys
- High 7.5
CVE-2026-0911subscriber+≤ 7.8.9.2
Hustle <= 7.8.9.2 - Authenticated (Subscriber+) Arbitrary File Upoload via Module Import
- Medium 5.3
CVE-2026-25431unauthenticated≤ 7.8.10.1
WordPress Hustle plugin <= 7.8.10.1 - Broken Access Control vulnerability
- Medium 5.3
CVE-2026-2263unauthenticated≤ 7.8.10.2
Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.10.2 - Missing Authorization to Unauthenticated Conversion Tracking Data Manipulation
- Medium 5.3
CVE-2026-24998unauthenticated≤ 7.8.9.2
WordPress Hustle plugin <= 7.8.9.2 - Sensitive Data Exposure vulnerability
- Medium 5.3
CVE-2024-10580unauthenticated≤ 7.8.5
Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unauthorized Form Submission
- Medium 5.3
CVE-2018-18576unauthenticated
The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/a
- Medium 4.3
CVE-2024-10579subscriber+≤ 7.8.5
Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unpublished Form Exposure
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).