The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file upload due to incorrect file type validation in the action_import_module() function in all versions up to and including 7.8.9.2. An authenticated attacker with a low-privileged role (e.g., Subscriber) who has been granted Hustle module permissions (module edit access) can access the Hustle admin page, obtain the required nonce, and upload arbitrary files to the server. This can enable remote code execution depending on server configuration and how uploaded files are handled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused exploit/Pentest helper for CVE-2026-0911 affecting the WPMU DEV Hustle WordPress plugin. It contains one Python exploit script and one README. The Python script is an authenticated web exploit that uses a supplied WordPress session cookie to access the Hustle admin interface, scrape a valid single_module_action_nonce from wp-admin/admin.php?page=hustle_popup_listing (or another specified admin page), and then send a multipart POST to wp-admin/admin-ajax.php using the Hustle AJAX action hustle_module_handle_single_action. The exploit abuses the Hustle module import workflow, specifically the weak upload validation path described in the CVE, to upload a file with an attacker-chosen remote filename such as a .php file. The script is operational rather than a bare PoC: it supports single-target and multi-target scanning, concurrent execution with ThreadPoolExecutor, manual or automatic nonce handling, custom cookies, custom payload files, optional use of a built-in PHP uploader payload, configurable SSL verification, timeout tuning, and immediate append-to-disk logging of successful hits. Its default payload is a benign PHP echo probe intended to test whether an uploaded PHP file can be written and executed. If the --uploader option is used, it uploads a simple PHP web form that can receive and save additional files, which materially increases post-exploitation capability. The exploit’s purpose is to detect and leverage the condition where Hustle writes an uploaded file during module import but fails to remove it after import validation fails, leaving an orphaned file in the WordPress uploads directory. The script then derives candidate URLs under wp-content/uploads/YYYY/MM/ and reports them as likely shell locations. Because it requires valid authentication and a nonce, this is not an unauthenticated internet-wide exploit; it is an authenticated abuse tool for a vulnerable plugin feature. The repository is not part of a larger exploit framework, is not fake, and is not merely a detector, since it performs the actual upload attempt with attacker-controlled content.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.