CVE Database /
CVE-2026-9656
CVE · Medium
CVE-2026-9656 — HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin] < 11.3.64
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-9656
|
HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin] < 11.3.64 |
Exposure of Sensitive Information to an Unauthorized Actor |
Medium
4.3
|
< 11.3.64
|
11.3.64 |
2026-07-16 |
—
|
CVE-2026-9656
A WordPress plugin called HubSpot All-In-One Marketing – Forms, Popups, Live Chat contains a security flaw that affects all versions up to 11.3.62. The issue lies in how the plugin handles sensitive information through JavaScript objects, allowing attackers with contributor-level access or higher to obtain plaintext OAuth refresh tokens for connected HubSpot accounts. This token can be used to manipulate data within the associated HubSpot tenant.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings