CVE · Medium

CVE-2026-9656 — HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin] < 11.3.64

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-9656 HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin] < 11.3.64 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.3 < 11.3.64 11.3.64 2026-07-16

CVE-2026-9656

A WordPress plugin called HubSpot All-In-One Marketing – Forms, Popups, Live Chat contains a security flaw that affects all versions up to 11.3.62. The issue lies in how the plugin handles sensitive information through JavaScript objects, allowing attackers with contributor-level access or higher to obtain plaintext OAuth refresh tokens for connected HubSpot accounts. This token can be used to manipulate data within the associated HubSpot tenant.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.