WP Clinic
Log in Sign up

CVE · High

CVE-2026-57736 — HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin] <= 11.3.56 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-57736 HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin] <= 11.3.56 (unfixed) Insertion of Sensitive Information Into Sent Data High 7.4 < 11.3.56 11.3.56 2026-07-01

CVE-2026-57736

The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.56. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.