# Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.14.2 - Missing Authorization to Authenticated (Subscriber+) Non-Public Post Title Disclosure

- **ID:** WPSEC-2026-0442
- **Plugin:** Hustle – Email Marketing, Lead Generation, Optins, Popups (`wordpress-popup`), https://wordpress.org/plugins/wordpress-popup/
- **Affected versions:** from 6.0.7 before 7.8.14.3
- **Fixed in:** 7.8.14.3 (Update to 7.8.14.3 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wordpress-popup
- **Fix released:** 2026-10-05
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0442/

## Description

The Hustle plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_new_condition_ids AJAX action in versions 6.0.7 up to, and including, 7.8.14.2. The handler accepted any post type and returned the IDs and titles of matching published posts without checking the user's permissions or limiting the search to public post types. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the titles of published entries of non-public post types, such as WooCommerce coupons, whose titles are the coupon codes.

## References

- https://wpsec.com/vuln/WPSEC-2026-0442/
- https://plugins.svn.wordpress.org/wordpress-popup/tags/7.8.14.3/
- https://wordpress.org/plugins/wordpress-popup/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0442/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
