HubSpot All-In-One Marketing <= 11.3.62 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script
medium
The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. This makes it possible for authenticated attackers, with contributor-level...
- CVSS:
- 4.3
- Affected:
- up to 11.3.62
- Fixed in:
- 11.3.64
- Disclosed:
- Jul 16, 2026
CVE-2026-9656 on NVD →
HubSpot All-In-One Marketing – Forms, Popups, Live Chat <= 11.3.55 - Authenticated (Contributor+) Information Exposure
medium
The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.55. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 11.3.55
- Fixed in:
- 11.3.56
- Disclosed:
- Jul 1, 2026
CVE-2026-57736 on NVD →
HubSpot All-In-One Marketing - Forms, Popups, Live Chat <= 11.3.32 - Missing Authorization to Authenticated (Contributor+) Installed Plugin Disclosure
medium
The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.32 via the leadin/public/admin/class-adminconstants.php file. This makes it possible for authenticated attackers, with Contributor-level access and...
- CVSS:
- 4.3
- Affected:
- up to 11.3.32
- Fixed in:
- 11.3.33
- Disclosed:
- Apr 23, 2026
CVE-2025-11762 on NVD →
HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics <= 11.1.22 - Authenticated (Contributor+) Stored Cross-Site Scripting via HubSpot Meeting Widget
medium
The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute of the HubSpot Meeting Widget in all versions up to, and including, 11.1.22 due to insufficient input sanitization and output escaping. This makes it possible for au...
- CVSS:
- 6.4
- Affected:
- up to 11.1.22
- Fixed in:
- 11.1.34
- Disclosed:
- Aug 29, 2024
CVE-2024-5879 on NVD →
HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics <= 8.8.13 - Server Side Request Forgery
high
The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could allow users with the edit_posts capability (by default contributor and above) to perform SSRF attacks
- CVSS:
- 8.1
- Affected:
- up to 8.8.15
- Fixed in:
- 8.8.15
- Disclosed:
- Apr 11, 2022
CVE-2022-1239 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database