Junglewise Threat Intelligence

CVE-2026-25431: WPMU DEV Hustle missing authorization in access control

CVE-2026-25431 · Severity: medium · CVSS 5.3 · Published 2026-05-12

Technologies: WPMU DEV Hustle. Vendors: WPMU DEV.

Executive brief

WPMU DEV Hustle, a popular WordPress plugin used for creating pop-ups, slide-ins, and email marketing forms, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to bypass intended security levels and perform actions that should be restricted to administrators. While the impact is considered low, it could allow attackers to interfere with the plugin's configuration or marketing campaigns.

Technical details

A missing authorization vulnerability (CWE-862) exists in the WPMU DEV Hustle plugin for WordPress through version 7.8.10.1. The flaw stems from insufficient validation of user permissions when interacting with certain plugin functions, allowing unauthenticated attackers to exploit incorrectly configured access control security levels. An attacker can leverage this to execute actions that should require higher privileges, potentially modifying plugin settings or data. The issue is resolved in version 7.8.10.2.

Affected products

  • WPMU DEV Hustle through 7.8.10.1

Timeline

  • 2025-12-26: other: Reported by Bao - BlueRock
  • 2026-05-12: disclosed: Published by Patchstack
  • 2026-05-12: patched: Version 7.8.10.2 released

References

Related threats