CVE-2026-9656: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in hubspotdev HubSpot All-In-One Marketing – Forms, Popups, Live Chat
The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the site's plaintext HubSpot OAuth refresh token exposed via the window.leadinConfig JavaScript object, which can then be used to access or modify data in the connected HubSpot tenant. Although the refresh token is stored at rest with AES-256-CTR encryption, decryption occurs server-side before the plaintext value is passed to wp_localize_script(), rendering the at-rest encryption ineffective against this exposure path.
AI Analysis
Technical Summary
CVE-2026-9656 is a sensitive information exposure vulnerability in the HubSpot All-In-One Marketing – Forms, Popups, Live Chat WordPress plugin. Authenticated users with contributor-level privileges or higher can extract the site's plaintext HubSpot OAuth refresh token from the window.leadinConfig JavaScript object. Although the token is encrypted at rest using AES-256-CTR, it is decrypted server-side before being passed to wp_localize_script(), exposing it in the client-side JavaScript context. This exposure could allow attackers to access or modify data in the associated HubSpot tenant. The vulnerability affects all versions up to and including 11.3.62. No official patch or remediation level has been published as of the data provided.
Potential Impact
An attacker with contributor-level or higher access to the WordPress site can obtain the plaintext HubSpot OAuth refresh token, which could be used to access or modify data in the connected HubSpot tenant. This compromises the confidentiality of sensitive authentication credentials and potentially the integrity of data managed through HubSpot. The vulnerability does not impact availability and requires authenticated access, limiting the attack surface.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict contributor-level access to trusted users only and monitor for suspicious activity related to HubSpot integrations. Avoid exposing sensitive tokens in client-side scripts. Follow vendor updates closely for any released patches or official mitigations.
CVE-2026-9656: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in hubspotdev HubSpot All-In-One Marketing – Forms, Popups, Live Chat
Description
The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the site's plaintext HubSpot OAuth refresh token exposed via the window.leadinConfig JavaScript object, which can then be used to access or modify data in the connected HubSpot tenant. Although the refresh token is stored at rest with AES-256-CTR encryption, decryption occurs server-side before the plaintext value is passed to wp_localize_script(), rendering the at-rest encryption ineffective against this exposure path.
CVSS v3.1
Score 4.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-9656 is a sensitive information exposure vulnerability in the HubSpot All-In-One Marketing – Forms, Popups, Live Chat WordPress plugin. Authenticated users with contributor-level privileges or higher can extract the site's plaintext HubSpot OAuth refresh token from the window.leadinConfig JavaScript object. Although the token is encrypted at rest using AES-256-CTR, it is decrypted server-side before being passed to wp_localize_script(), exposing it in the client-side JavaScript context. This exposure could allow attackers to access or modify data in the associated HubSpot tenant. The vulnerability affects all versions up to and including 11.3.62. No official patch or remediation level has been published as of the data provided.
Potential Impact
An attacker with contributor-level or higher access to the WordPress site can obtain the plaintext HubSpot OAuth refresh token, which could be used to access or modify data in the connected HubSpot tenant. This compromises the confidentiality of sensitive authentication credentials and potentially the integrity of data managed through HubSpot. The vulnerability does not impact availability and requires authenticated access, limiting the attack surface.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict contributor-level access to trusted users only and monitor for suspicious activity related to HubSpot integrations. Avoid exposing sensitive tokens in client-side scripts. Follow vendor updates closely for any released patches or official mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-05-26T20:23:14.339Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a59dabd68715ace439188ae
Added to database: 07/17/2026, 07:33:17 UTC
Last enriched: 07/17/2026, 07:47:29 UTC
Last updated: 08/30/2026, 22:52:14 UTC
Views: 62
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.