{
 "id": "WPSEC-2026-0442",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0442/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0442/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0442/index.md",
 "title": "Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.14.2 - Missing Authorization to Authenticated (Subscriber+) Non-Public Post Title Disclosure",
 "description": "The Hustle plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_new_condition_ids AJAX action in versions 6.0.7 up to, and including, 7.8.14.2. The handler accepted any post type and returned the IDs and titles of matching published posts without checking the user's permissions or limiting the search to public post types. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the titles of published entries of non-public post types, such as WooCommerce coupons, whose titles are the coupon codes.",
 "plugin": {
  "slug": "wordpress-popup",
  "name": "Hustle – Email Marketing, Lead Generation, Optins, Popups",
  "full_name": "Hustle – Email Marketing, Lead Generation, Optins, Popups",
  "wordpress_org": "https://wordpress.org/plugins/wordpress-popup/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wordpress-popup/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wordpress-popup"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-862"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "6.0.7",
    "from_inclusive": true,
    "to": "7.8.14.3",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 6.0.7 before 7.8.14.3"
  ]
 },
 "introduced_in": "6.0.7",
 "fixed_in": "7.8.14.3",
 "remediation": "Update to 7.8.14.3 or later.",
 "fix_released": "2026-10-05T06:09:01+00:00",
 "published": "2026-10-06T14:47:47+00:00",
 "updated": "2026-10-06T14:18:54.075870+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0442/",
  "https://plugins.svn.wordpress.org/wordpress-popup/tags/7.8.14.3/",
  "https://wordpress.org/plugins/wordpress-popup/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wordpress-popup",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-06"
 }
}