The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form submissions due to a missing capability check on the submit_form() function in all versions up to, and including, 7.8.5. This makes it possible for unauthenticated attackers to submit unpublished forms.
Metrics
Affected Vendors & Products
References
History
Wed, 27 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpmudev
Wpmudev hustle |
|
CPEs | cpe:2.3:a:wpmudev:hustle:*:*:*:*:*:*:*:* | |
Vendors & Products |
Wpmudev
Wpmudev hustle |
|
Metrics |
ssvc
|
Wed, 27 Nov 2024 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form submissions due to a missing capability check on the submit_form() function in all versions up to, and including, 7.8.5. This makes it possible for unauthenticated attackers to submit unpublished forms. | |
Title | Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unauthorized Form Submission | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-11-27T06:41:28.378Z
Updated: 2024-11-27T14:40:32.667Z
Reserved: 2024-10-31T12:57:12.812Z
Link: CVE-2024-10580
Vulnrichment
Updated: 2024-11-27T14:36:16.966Z
NVD
Status : Received
Published: 2024-11-27T07:15:07.920
Modified: 2024-11-27T07:15:07.920
Link: CVE-2024-10580
Redhat
No data.