Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.14.2 - Missing Authorization to Authenticated (Subscriber+) Non-Public Post Title Disclosure
- ID
- WPSEC-2026-0442
- Plugin
- Hustle – Email Marketing, Lead Generation, Optins, Popups (wordpress-popup)
- Affected
- from 6.0.7 before 7.8.14.3
- Remediation
- Update to 7.8.14.3 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-862
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
- Attack surface
- Hustle – Email Marketing, Lead Generation, Optins, Popups on WPSec AttackSurface
- Fix released
- Published
Description
The Hustle plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_new_condition_ids AJAX action in versions 6.0.7 up to, and including, 7.8.14.2. The handler accepted any post type and returned the IDs and titles of matching published posts without checking the user's permissions or limiting the search to public post types. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the titles of published entries of non-public post types, such as WooCommerce coupons, whose titles are the coupon codes.
References
- https://wpsec.com/vuln/WPSEC-2026-0442/
- https://plugins.svn.wordpress.org/wordpress-popup/tags/7.8.14.3/
- https://wordpress.org/plugins/wordpress-popup/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS