CVE-2018-18576: Incsub Hustle

Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.

The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI.

Affected products

  • Incsub Hustle: up to and including 6.0.5

Published 2020-03-17. Last modified 2026-06-17.