Impact
A vulnerability in the HubSpot WordPress plugin allows an attacker to retrieve embedded sensitive data that the plugin sends, potentially exposing confidential information that the plugin handles or transmits to HubSpot’s servers. The flaw corresponds to CWE-201, indicating unauthorized disclosure of sensitive information.
Affected Systems
WordPress sites running the HubSpot plugin in any version up to and including 11.3.51 are affected. Versions newer than 11.3.51 are not vulnerable.
Risk and Exploitability
The CVSS score of 7.4 places the issue in the high severity range, and the EPSS score is <1%, indicating limited public exploitation data. It is not listed in the KEV catalog. The vulnerability enables retrieval of embedded sensitive data, which can expose confidential information. Likely attack paths involve web requests to the WordPress site that trigger the HubSpot plugin to send data; an attacker with web access could craft or manipulate HTTP requests or the plugin’s configuration to force transmission of sensitive values, allowing them to capture such data in transit or via external endpoints.
OpenCVE Enrichment