High 7.5
2026-01-24< 7.8.9.3
Hustle <= 7.8.9.2 - Authenticated (Subscriber+) Arbitrary File Upoload via Module Import
Minimum safe version
7.8.11
Update to 7.8.11 or later to address 9 fixable vulnerabilities
Hustle <= 7.8.9.2 - Authenticated (Subscriber+) Arbitrary File Upoload via Module Import
Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.10.2 - Missing Authorization to Unauthenticated Conversion Tracking Data Manipulation
CVE-2026-24998
CVE-2024-10580
CVE-2024-10579
WordPress Hustle Plugin < 7.8.5 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-0368
Hustle <= 7.6.4 = Authenticated (Administrator+) Stored Cross-Site Scripting
WordPress Hustle – Pop-Ups, Slide-ins and Email Opt-ins plugin <= 6.0.7 - Unauthenticated CSV Injection vulnerability
CVE-2018-18576