MEDIUM
wpmudev
CVE published 2026-04-08
CVE-2026-2263
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hustle_module_converted' AJAX action in all versions up to, and including, 7.8.10.2. This vulnerability allows unauthenticated attackers to forge conversion tracking events for any Hustle module, including draft modules that are nev [truncated]