Executive brief
The Hustle plugin for WordPress, which is used for email marketing and lead generation popups, contains a security flaw that allows unauthorized users to tamper with marketing data. An attacker can remotely trigger fake conversion events, even for marketing campaigns that are not currently active or visible to the public. This can lead to inaccurate business analytics, skewed performance metrics, and unreliable marketing reports.
Technical details
The vulnerability is classified as a missing authorization check (CWE-862) within the 'hustle_module_converted' AJAX action. Because the plugin fails to verify the permissions of the user initiating the request, any unauthenticated network actor can send forged requests to the server. This allows for the creation of fraudulent conversion tracking events for any Hustle module, including those in draft status. The primary impact is the loss of integrity for marketing and conversion statistics. The issue is addressed in version 7.8.11.
Affected products
- WPMU DEV Hustle – Email Marketing, Lead Generation, Optins, Popups Up to and including 7.8.10.2
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-08: patched: Fixed in version 7.8.11
References
- https://plugins.trac.wordpress.org/browser/wordpress-popup/tags/7.8.9.3/inc/front/hustle-module-front-ajax.php
- https://plugins.trac.wordpress.org/browser/wordpress-popup/tags/7.8.9.3/inc/front/hustle-module-front-ajax.php
- https://plugins.trac.wordpress.org/browser/wordpress-popup/tags/7.8.9.3/inc/front/hustle-module-front.php
- https://plugins.trac.wordpress.org/changeset?old_path=/wordpress-popup/tags/7.8.10.2&new_path=/wordpress-popup/tags/7.8.11
- https://www.wordfence.com/threat-intel/vulnerabilities/id/2305462c-0a00-4423-8dc2-e32628c4864d?source=cve