CVE-2026-24998: Wpmu Dev - Your All-In-One WordPress Platform Hustle

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hustle wordpress-popup allows Retrieve Embedded Sensitive Data.This issue affects Hustle: from n/a through <= 7.8.9.2.

Affected products

Published 2026-02-03. Last modified 2026-06-17.