Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.14.2 - Missing Authorization to Authenticated (Subscriber+) Non-Public Post Title Disclosure

Medium 4.3 CWE-862Fixed in 7.8.14.3
ID
WPSEC-2026-0442
Plugin
Hustle – Email Marketing, Lead Generation, Optins, Popups (wordpress-popup)
Affected
from 6.0.7 before 7.8.14.3
Remediation
Update to 7.8.14.3 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-862
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
Hustle – Email Marketing, Lead Generation, Optins, Popups on WPSec AttackSurface
Fix released
Published

Description

The Hustle plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_new_condition_ids AJAX action in versions 6.0.7 up to, and including, 7.8.14.2. The handler accepted any post type and returned the IDs and titles of matching published posts without checking the user's permissions or limiting the search to public post types. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the titles of published entries of non-public post types, such as WooCommerce coupons, whose titles are the coupon codes.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0