Description
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via hardcoded API Keys. This makes it possible for unauthenticated attackers to extract sensitive data including PII.
Published: 2024-03-13
Score: 8.6 High
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-16164 The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via hardcoded API Keys. This makes it possible for unauthenticated attackers to extract sensitive data including PII.
History

Wed, 08 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Title Hustle <= 7.8.3 - Sensitive Information Exposure via Exposed Hubspot API Keys
Weaknesses CWE-522

Tue, 11 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Wpmudev
Wpmudev hustle
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:wpmudev:hustle:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpmudev
Wpmudev hustle

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:30:15.925Z

Reserved: 2024-01-09T19:55:46.479Z

Link: CVE-2024-0368

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:49.506Z

cve-icon NVD

Status : Modified

Published: 2024-03-13T16:15:10.623

Modified: 2026-04-08T19:19:08.890

Link: CVE-2024-0368

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses