Impact
The Hustle WordPress plugin before 7.8.14.2 allows unauthenticated users to submit form values that contain WordPress shortcodes. When the plugin substitutes these values into its success message, the guard that is intended to neutralize shortcodes can be bypassed by nesting, so the shortcodes are executed by WordPress. This flaw corresponds to CWE‑74, Improper Neutralization of Input During Web Page Generation, and it enables an attacker to run any shortcode registered on the site, potentially leading to remote code execution within the WordPress context limited to the capabilities of those shortcodes.
Affected Systems
WordPress sites that use the Hustle plugin with a version older than 7.8.14.2 are affected. No further version constraints are specified beyond this cutoff.
Risk and Exploitability
The CVSS score of 4.8 indicates low‑to‑moderate impact, and the EPSS score of less than 1% reflects a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers exploit the flaw by submitting an unauthenticated form that contains a crafted shortcode, which is then evaluated in the success message rendering path.
OpenCVE Enrichment