CVE-2024-10580: Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unauthorized Form Submission
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form submissions due to a missing capability check on the submitform() function in all versions up to, and including, 7.8.5. This makes it possible for unauthenticated attackers to submit unpublished forms.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10580?
CVE-2024-10580 has a high severity level due to its potential for unauthorized form submissions.
How do I fix CVE-2024-10580?
To fix CVE-2024-10580, update the Hustle – Email Marketing, Lead Generation, Optins, Popups plugin to version 7.8.6 or later.
Who is affected by CVE-2024-10580?
All users of the Hustle – Email Marketing, Lead Generation, Optins, Popups plugin up to version 7.8.5 are affected by CVE-2024-10580.
What type of vulnerability is CVE-2024-10580?
CVE-2024-10580 is a vulnerability related to unauthorized access due to a missing capability check.
Can CVE-2024-10580 impact my website's data security?
Yes, CVE-2024-10580 can compromise your website's data security by allowing unauthenticated users to submit forms.