First published: Tue Mar 17 2020(Updated: )
The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hustle | <=6.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18576 is a vulnerability in The Hustle (aka wordpress-popup) plugin for WordPress that allows Directory Traversal to obtain a directory listing.
CVE-2018-18576 has a severity rating of 5.3 (Medium).
The Hustle (aka wordpress-popup) plugin versions up to and including 6.0.5 for WordPress are affected by CVE-2018-18576.
To fix CVE-2018-18576, it is recommended to update The Hustle (aka wordpress-popup) plugin to a version that is not vulnerable.
The Common Weakness Enumeration (CWE) ID for CVE-2018-18576 is CWE-22.