Description
Insertion of Sensitive Information Into Sent Data vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Retrieve Embedded Sensitive Data.This issue affects Integration for Contact Form 7 HubSpot: from n/a through <= 1.4.3.
Published: 2026-01-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Update Plugin
AI Analysis

Impact

The flaw involves the insertion of sensitive information into data that is sent from the WordPress Integration for Contact Form 7 HubSpot plugin. When the plugin processes form submissions it can expose confidential data to the target HubSpot endpoint. The data leakage potentially compromises confidentiality and may allow an attacker to steal personally identifiable or business‑critical information. The vulnerability is categorized as CWE‑201 (Sensitive Data Exposure).

Affected Systems

Affected are deployments of the CRM Perks: Integration for Contact Form 7 HubSpot plugin, version 1.4.3 and all earlier releases. The nature of the product is a WordPress plugin that forwards form data to HubSpot.

Risk and Exploitability

The CVSS base score of 5.4 indicates a moderate risk while the EPSS score of less than 1% suggests that exploitation attempts are expected to be very rare. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could submit specially crafted form data that triggers the plugin to send sensitive fields to HubSpot. No additional authentication or privilege escalation steps are described, so the attack surface is limited to sites that have the vulnerable plugin installed and have exposed contact forms. The overall threat remains moderate, but the low EPSS indicates that widespread exploitation is unlikely at present.

Generated by OpenCVE AI on April 16, 2026 at 17:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Integration for Contact Form 7 HubSpot plugin to a version newer than 1.4.3
  • Disable or uninstall the vulnerable plugin if an immediate upgrade is not possible to prevent further data leakage
  • Monitor form submissions and HubSpot inbound traffic for evidence of unintended sensitive data transmission

Generated by OpenCVE AI on April 16, 2026 at 17:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Mon, 26 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Mon, 26 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Crm Perks
Crm Perks integration For Contact Form 7 Hubspot
Wordpress
Wordpress wordpress
Vendors & Products Crm Perks
Crm Perks integration For Contact Form 7 Hubspot
Wordpress
Wordpress wordpress

Fri, 23 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Retrieve Embedded Sensitive Data.This issue affects Integration for Contact Form 7 HubSpot: from n/a through <= 1.4.3.
Title WordPress Integration for Contact Form 7 HubSpot plugin <= 1.4.3 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References

Subscriptions

Crm Perks Integration For Contact Form 7 Hubspot
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-23T14:14:06.083Z

Reserved: 2026-01-23T12:31:51.716Z

Link: CVE-2026-24559

cve-icon Vulnrichment

Updated: 2026-01-26T17:28:01.010Z

cve-icon NVD

Status : Deferred

Published: 2026-01-23T15:16:13.187

Modified: 2026-04-23T15:36:49.327

Link: CVE-2026-24559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T18:00:11Z

Weaknesses