CVE-2026-2263: Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.10.2 - Missing Authorization to Unauthenticated Conversion Tracking Data Manipulation
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hustlemoduleconverted' AJAX action in all versions up to, and including, 7.8.10.2. This makes it possible for unauthenticated attackers to forge conversion tracking events for any Hustle module, including draft modules that are never displayed to users, thereby manipulating marketing analytics and conversion statistics.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2263?
The severity of CVE-2026-2263 is rated as medium with a score of 5.3.
How do I fix CVE-2026-2263?
To fix CVE-2026-2263, update the Hustle plugin to version 7.8.10.3 or later that includes the necessary security patch.
What is the impact of CVE-2026-2263?
CVE-2026-2263 allows unauthenticated users to modify conversion tracking data due to a missing authorization check.
Which versions are affected by CVE-2026-2263?
CVE-2026-2263 affects all versions of the Hustle plugin up to and including 7.8.10.2.
Who is the vendor for the Hustle plugin related to CVE-2026-2263?
The vendor for the Hustle plugin related to CVE-2026-2263 is WPMU DEV.