plugin

Leadin Vulnerabilities

5 known security issues reported for the Leadin WordPress plugin. Most recent disclosed Jul 16, 2026.

1 high 4 medium

Running Leadin on your site? Check whether your installed version is affected.

Scan your site free

HubSpot All-In-One Marketing <= 11.3.62 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script

medium

The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. This makes it possible for authenticated attackers, with contributor-level...

CVSS:
4.3
Affected:
up to 11.3.62
Fixed in:
11.3.64
Disclosed:
Jul 16, 2026

CVE-2026-9656 on NVD →

HubSpot All-In-One Marketing – Forms, Popups, Live Chat <= 11.3.55 - Authenticated (Contributor+) Information Exposure

medium

The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.55. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 11.3.55
Fixed in:
11.3.56
Disclosed:
Jul 1, 2026

CVE-2026-57736 on NVD →

HubSpot All-In-One Marketing - Forms, Popups, Live Chat <= 11.3.32 - Missing Authorization to Authenticated (Contributor+) Installed Plugin Disclosure

medium

The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.32 via the leadin/public/admin/class-adminconstants.php file. This makes it possible for authenticated attackers, with Contributor-level access and...

CVSS:
4.3
Affected:
up to 11.3.32
Fixed in:
11.3.33
Disclosed:
Apr 23, 2026

CVE-2025-11762 on NVD →

HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics <= 11.1.22 - Authenticated (Contributor+) Stored Cross-Site Scripting via HubSpot Meeting Widget

medium

The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute of the HubSpot Meeting Widget in all versions up to, and including, 11.1.22 due to insufficient input sanitization and output escaping. This makes it possible for au...

CVSS:
6.4
Affected:
up to 11.1.22
Fixed in:
11.1.34
Disclosed:
Aug 29, 2024

CVE-2024-5879 on NVD →

HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics <= 8.8.13 - Server Side Request Forgery

high

The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could allow users with the edit_posts capability (by default contributor and above) to perform SSRF attacks

CVSS:
8.1
Affected:
up to 8.8.15
Fixed in:
8.8.15
Disclosed:
Apr 11, 2022

CVE-2022-1239 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database