CVE · High

CVE-2024-7389 — Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.29.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-7389 Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.29.2 Insufficiently Protected Credentials High 7.5 < 1.29.2 1.29.2 2024-08-01

CVE-2024-7389

A security flaw exists in Forminator, a WordPress plugin, affecting all versions prior to 1.29.2. The issue resides in the class-forminator-addon-hubspot-wp-api.php file and can be exploited by unauthorized parties to obtain the HubSpot developer API key. This compromised access allows for illicit alterations to the plugin's integration with HubSpot or disclosure of user data tied to that integration.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.