Junglewise Threat Intelligence

CVE-2026-80440: Hustle arbitrary shortcode execution via form placeholders

CVE-2026-80440 · Severity: medium · CVSS 4.8 · Published 2026-09-09

Technologies: Hustle.

Executive brief

The Hustle WordPress plugin, used to create opt-in forms and popups, fails to properly sanitize user-submitted form values before inserting them into success messages. An attacker can inject nested shortcodes that bypass the plugin's filter, allowing execution of arbitrary shortcodes without authentication. This could expose sensitive site data or trigger unintended plugin functionality depending on which shortcodes are registered.

Technical details

The vulnerability is a shortcode injection flaw in the form submission handler. When users submit form data, the plugin inserts their responses into a success message template using placeholders (e.g., {first_name}). The plugin attempts to strip shortcodes but uses a guard that can be defeated by nesting brackets—submitting [[gallery]] results in the outer brackets being removed, leaving [gallery] to execute. The attack requires no authentication and exploits the form_submit_nonce that is publicly distributed to all page visitors. While the email field is protected by its own format validator, any unvalidated field is exploitable. The vulnerability affects versions 7.0.0.1 through 7.8.14.1; a fix was released in version 7.8.14.2.

Affected products

  • Hustle Hustle 7.0.0.1 through 7.8.14.1

Timeline

  • 2026-09-07: disclosed
  • 2026-09-09: patched: Fixed in version 7.8.14.2

References