Directory Traversal Vulnerability in Hustle Plugin for WordPress
CVE-2018-18576
5.3MEDIUM
What is CVE-2018-18576?
The Hustle plugin, commonly known as wordpress-popup, is susceptible to a directory traversal vulnerability that allows an attacker to access sensitive directory listings. This flaw exists in versions up to 6.0.5 of the plugin, through accessing the URI views/admin/dashboard/. Exploiting this vulnerability could enable malicious actors to enumerate files and directories, potentially leading to further exploitation and data breaches.