WordPress security by component
Hustle
Plugin description
Hustle is a WordPress component with 8 published CVE records in this archive. The latest tracked vulnerability was published May 12, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
wordpress-popupLatest vulnerability
CVE-2026-25431: Hustle: A security weakness
Hustle is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 7.8.10.1.
| Safe version |
|
||
|---|---|---|---|
| May 12, 2026 |
CVE-2026-25431
Hustle: A security weakness
Hustle is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 7.8.10.1.
|
7.8.10.2 |
CVE5.3
NVDPending
|
| Apr 08, 2026 |
CVE-2026-2263
Hustle – Email Marketing, Lead Generation, Optins, Popups: A security weakness
Hustle – Email Marketing, Lead Generation, Optins, Popups is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 7.8.10.2.
|
> 7.8.10.2 |
CVE5.3
NVDPending
|
| Feb 03, 2026 |
CVE-2026-24998
Hustle: A security weakness
Hustle is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Nov 27, 2024 |
CVE-2024-10580
Hustle – Email Marketing, Lead Generation, Optins, Popups: A security weakness
Hustle – Email Marketing, Lead Generation, Optins, Popups is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Nov 26, 2024 |
CVE-2024-10579
Hustle – Email Marketing, Lead Generation, Optins, Popups: A security weakness
Hustle – Email Marketing, Lead Generation, Optins, Popups is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Mar 13, 2024 |
CVE-2024-0368
Hustle – Email Marketing, Lead Generation, Optins, Popups: Sensitive information exposure
Hustle – Email Marketing, Lead Generation, Optins, Popups is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE8.6
NVDPending
|
| Mar 17, 2020 |
CVE-2018-18576
Wordpress Popup: Filesystem traversal
Wordpress Popup is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| May 29, 2019 |
CVE-2019-11872
Wordpress Popup: A security weakness
Wordpress Popup is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.8
NVD8.8
|