PT-2026-60729 · WordPress · Hubspot All-In-One Marketing

·

CVE-2026-9656

·

Published

2026-07-16

·

Updated

2026-07-17

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress versions prior to 11.3.63
Description Sensitive information exposure occurs via the window.leadinConfig JavaScript object used in the wp localize script() function. Authenticated attackers with contributor-level access or higher can extract the site's plaintext HubSpot OAuth refresh token. This token allows unauthorized access to or modification of data within the connected HubSpot tenant. Although the token is encrypted at rest using AES-256-CTR (a symmetric encryption algorithm that uses a counter to turn a block cipher into a stream cipher), it is decrypted server-side before being passed to the JavaScript object, making the encryption ineffective.
Recommendations Update the plugin to a version newer than 11.3.62.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9656

Affected Products

Hubspot All-In-One Marketing