The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form submissions due to a missing capability check on the submit_form() function in all versions up to, and including, 7.8.5. This makes it possible for unauthenticated attackers to submit unpublished forms.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-11-27 07:15
Updated : 2024-11-27 07:15
NVD link : CVE-2024-10580
Mitre link : CVE-2024-10580
CVE.ORG link : CVE-2024-10580
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization