Junglewise Threat Intelligence

CVE-2026-57736: HubSpot WordPress Plugin sensitive data exposure

CVE-2026-57736 · Severity: high · CVSS 7.4 · Published 2026-07-01

Executive brief

A security vulnerability exists in the HubSpot plugin for WordPress, which is used to integrate marketing and CRM tools into websites. This flaw allows an attacker with basic user access to view sensitive information that should normally be protected. Exposure of this data could lead to further unauthorized access or compromise of the website's operations and customer information.

Technical details

The HubSpot WordPress plugin (leadin) through version 11.3.51 is vulnerable to sensitive data exposure (CWE-201). The vulnerability occurs when the application inserts sensitive information into data sent to the user, allowing an attacker to retrieve embedded sensitive data. The attack vector is network-based and requires 'Contributor' level privileges (PR:L). While the CVSS score is 7.4, the vendor/researcher notes suggest a low likelihood of exploitation. As of the advisory date, no official patch has been confirmed, though users are advised to monitor for updates to the 'leadin' plugin.

Affected products

  • HubSpot HubSpot - Marketing Software, CRM, Sales, & Service (leadin) through 11.3.51

Timeline

  • 2026-04-21: other: Reported by Jakub Herman
  • 2026-07-01: advisory: Published by Patchstack and NVD

References