CVE-2026-0911

HIGH

Hustle - Email Marketing - File Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-0911. PoCs published by murrez.

AI-analyzed exploit summary This repository contains a functional exploit PoC for CVE-2026-0911, targeting a file upload vulnerability in the Hustle WordPress plugin (versions <= 7.8.9.2). The exploit leverages weak file extension checks and improper cleanup of failed imports to achieve arbitrary file upload, potentially leading to RCE.

Description

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the action_import_module() function in all versions up to, and including, 7.8.9.2. This makes it possible for authenticated attackers, with a lower-privileged role (e.g., Subscriber-level access and above), to upload arbitrary files on the affected site's server which may make remote code execution possible. Successful exploitation requires an admin to grant Hustle module permissions (or module edit access) to the low-privileged user so they can access the Hustle admin page and obtain the required nonce.

Exploits (1)

github WORKING POC
by murrez · pythonpoc
https://github.com/murrez/CVE-2026-0911

This repository contains a functional exploit PoC for CVE-2026-0911, targeting a file upload vulnerability in the Hustle WordPress plugin (versions <= 7.8.9.2). The exploit leverages weak file extension checks and improper cleanup of failed imports to achieve arbitrary file upload, potentially leading to RCE.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Hustle WordPress plugin <= 7.8.9.2
Auth required
Prerequisites: Valid WordPress admin session with Hustle management access · Hustle single_action nonce · Module ID set to 0 for new import path
devstral-2 · analyzed Apr 27, 2026 Full analysis →

Scores

CVSS v3 7.5
EPSS 0.0054
EPSS Percentile 41.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
wpmudev/Hustle – Email Marketing, Lead Generation, Optins, Popups < 7.8.9.2
Published Jan 24, 2026
Tracked Since Feb 18, 2026