The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via hardcoded API Keys. This makes it possible for unauthenticated attackers to extract sensitive data including PII.
History

Tue, 11 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Wpmudev
Wpmudev hustle
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:wpmudev:hustle:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpmudev
Wpmudev hustle

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-02T20:39:27.616Z

Reserved: 2024-01-09T19:55:46.479Z

Link: CVE-2024-0368

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:49.506Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-13T16:15:10.623

Modified: 2025-03-11T16:51:23.420

Link: CVE-2024-0368

cve-icon Redhat

No data.