CVE Database /
CVE-2024-5879
CVE · Medium
CVE-2024-5879 — HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin] < 11.1.34
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-5879
|
HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin] < 11.1.34 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 11.1.34
|
11.1.34 |
2024-08-29 |
—
|
CVE-2024-5879
The HubSpot plugin for WordPress contains a security flaw in its Meeting Widget's URL attribute, allowing malicious users with at least Contributor privileges to insert unauthorized code into website pages. This vulnerability arises from inadequate filtering of input data and failure to properly encode output, enabling attackers to inject arbitrary scripts that will run when affected pages are accessed. The issue affects all plugin versions up to 11.1.22.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings