PT-2026-60729 · WordPress · Hubspot All-In-One Marketing
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress versions prior to 11.3.63
Description
Sensitive information exposure occurs via the
window.leadinConfig JavaScript object used in the wp localize script() function. Authenticated attackers with contributor-level access or higher can extract the site's plaintext HubSpot OAuth refresh token. This token allows unauthorized access to or modification of data within the connected HubSpot tenant. Although the token is encrypted at rest using AES-256-CTR (a symmetric encryption algorithm that uses a counter to turn a block cipher into a stream cipher), it is decrypted server-side before being passed to the JavaScript object, making the encryption ineffective.Recommendations
Update the plugin to a version newer than 11.3.62.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hubspot All-In-One Marketing