Skip to content
Noroxi

Hustle – Email Marketing, Lead Generation, Optins, Popups

wordpress-popup · plugin

Known security vulnerabilities for Hustle – Email Marketing, Lead Generation, Optins, Popups. Find out in seconds which version runs on your site with WP Lens.

9 known vulnerabilities

7 exploitable without logging in · 2 with public exploit code · latest May 12, 2026

Listed on wordpress.org · latest 7.8.14.2 · last updated Aug 31, 2026 · 90K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2019-11872unauthenticated · needs a click

    The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a

    High 8.8
  • CVE-2024-0368unauthenticated≤ 7.8.3

    Hustle <= 7.8.3 - Sensitive Information Exposure via Exposed Hubspot API Keys

    High 8.6
  • CVE-2026-0911subscriber+≤ 7.8.9.2

    Hustle <= 7.8.9.2 - Authenticated (Subscriber+) Arbitrary File Upoload via Module Import

    High 7.5
  • CVE-2026-25431unauthenticated≤ 7.8.10.1

    WordPress Hustle plugin <= 7.8.10.1 - Broken Access Control vulnerability

    Medium 5.3
  • CVE-2026-2263unauthenticated≤ 7.8.10.2

    Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.10.2 - Missing Authorization to Unauthenticated Conversion Tracking Data Manipulation

    Medium 5.3
  • CVE-2026-24998unauthenticated≤ 7.8.9.2

    WordPress Hustle plugin <= 7.8.9.2 - Sensitive Data Exposure vulnerability

    Medium 5.3
  • CVE-2024-10580unauthenticated≤ 7.8.5

    Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unauthorized Form Submission

    Medium 5.3
  • CVE-2018-18576unauthenticated

    The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/a

    Medium 5.3
  • CVE-2024-10579subscriber+≤ 7.8.5

    Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unpublished Form Exposure

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory