CVE-2026-24998: WordPress Hustle plugin <= 7.8.9.2 - Sensitive Data Exposure vulnerability
Published Feb 3, 2026
·Updated
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hustle wordpress-popup allows Retrieve Embedded Sensitive Data.This issue affects Hustle: from n/a through <= 7.8.9.2.
Affected Software
2 affected components
WPMU DEV Hustle<=7.8.9.2
wordpress-popup<=7.8.9.2
Event History
Feb 3, 2026
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-24998?
CVE-2026-24998 has a moderate severity due to its potential for sensitive data exposure.
2
How do I fix CVE-2026-24998?
To fix CVE-2026-24998, update the WPMU DEV Hustle plugin to version 7.8.9.3 or later.
3
What types of sensitive data are exposed in CVE-2026-24998?
CVE-2026-24998 potentially exposes embedded sensitive system information to unauthorized users.
4
Which versions of Hustle are affected by CVE-2026-24998?
CVE-2026-24998 affects WPMU DEV Hustle plugin versions up to and including 7.8.9.2.
5
How can I determine if my site is vulnerable to CVE-2026-24998?
Check your current version of the WPMU DEV Hustle plugin to see if it is 7.8.9.2 or earlier to assess vulnerability.