CVE-2024-10579: Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unpublished Form Exposure
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the previewmodule() function in all versions up to, and including, 7.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view unpublished forms.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10579?
CVE-2024-10579 is considered a critical vulnerability due to unauthorized access to data.
How do I fix CVE-2024-10579?
To fix CVE-2024-10579, update the Hustle Email Marketing, Lead Generation, Optins, Popups plugin to version 7.8.6 or later.
Who is affected by CVE-2024-10579?
Anyone using Hustle Email Marketing, Lead Generation, Optins, Popups plugin versions up to and including 7.8.5 is affected by CVE-2024-10579.
What does CVE-2024-10579 exploit?
CVE-2024-10579 exploits a missing capability check in the preview_module() function.
What type of vulnerability is CVE-2024-10579?
CVE-2024-10579 is a security vulnerability relating to unauthorized data access.