CVE-2026-9656
WordPress Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-9656 is a Sensitive Information Exposure vulnerability in the HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress, classified as CWE-200. All versions up to and including 11.3.62 are affected. The flaw allows authenticated attackers with contributor-level access or above to extract the site's plaintext HubSpot OAuth refresh token exposed via the window.leadinConfig JavaScript object. It was published on July 17, 2026, with a patch available in version 11.3.64. The CVSS v3.1 base score is 4.3 (Medium) (GitHub Advisory).

Détails techniques

The root cause is improper exposure of sensitive credentials to client-side JavaScript (CWE-200). Although the HubSpot OAuth refresh token is stored at rest using AES-256-CTR encryption, the plugin decrypts the token server-side and passes the plaintext value to WordPress's wp_localize_script() function, which embeds it in the page's JavaScript as part of the window.leadinConfig object. This renders the at-rest encryption entirely ineffective against this exposure path. Relevant code paths have been identified in class-adminconstants.php, class-gutenberg.php, class-oauth.php, and class-assetsmanager.php of the plugin (GitHub Advisory, Wordfence).

Impact

Successful exploitation allows an authenticated attacker with contributor-level WordPress access to obtain the plaintext HubSpot OAuth refresh token, which can then be used to access or modify data within the connected HubSpot tenant. This creates a risk of unauthorized data exfiltration, manipulation of marketing data, contact records, or other HubSpot-managed assets. There is no direct availability or integrity impact on the WordPress site itself, but the compromise of the HubSpot tenant could have significant downstream business consequences (GitHub Advisory).

Étapes d’exploitation

  1. Gain Contributor Access: Obtain or create a WordPress account with at least contributor-level privileges on the target site (e.g., via credential stuffing, phishing, or registration if open).
  2. Navigate to a Page Using the Plugin: Log in and visit any WordPress page or post where the HubSpot plugin loads its JavaScript assets (e.g., a page with a HubSpot form or popup).
  3. Inspect the Page JavaScript: Open browser developer tools and search the page source or JavaScript console for the window.leadinConfig object, which is injected by wp_localize_script().
  4. Extract the Refresh Token: Locate the plaintext HubSpot OAuth refresh token within the window.leadinConfig object in the page's JavaScript.
  5. Abuse the Token: Use the extracted refresh token to authenticate against the HubSpot API, obtaining a new access token and gaining the ability to read or modify data in the connected HubSpot tenant (GitHub Advisory).

Indicateurs de compromis

  • Logs: WordPress authentication logs showing contributor-level logins from unfamiliar IP addresses or at unusual times; HubSpot audit logs showing API access or data modifications not initiated by known users or integrations.
  • Network: Unexpected API calls to HubSpot endpoints (e.g., api.hubapi.com) originating from IP addresses not associated with the WordPress server or known administrators.
  • HubSpot Activity: Unauthorized changes to contacts, forms, or marketing data in the HubSpot tenant; new OAuth tokens generated without corresponding administrative action.

Atténuation et solutions de contournement

Update the HubSpot All-In-One Marketing plugin to version 11.3.64 or later, which addresses this exposure (changeset available between tags 11.3.62 and 11.3.64) (GitHub Advisory). As an interim measure, restrict contributor-level and above WordPress user access to only trusted personnel. If unauthorized access is suspected, revoke the exposed HubSpot OAuth refresh token from the HubSpot application settings and re-authorize the integration. Monitor the HubSpot tenant for unauthorized access or unexpected data changes.

Réactions de la communauté

The vulnerability was reported through Wordfence's threat intelligence platform and published to the GitHub Advisory Database on July 17, 2026 (Wordfence, GitHub Advisory). No significant broader media coverage or notable researcher commentary beyond the initial advisory has been observed at this time.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté WordPress Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-13147CRITICAL9.1
  • kirki
NonOuiJul 20, 2026
CVE-2026-9833HIGH7.1
  • tag-groups
NonOuiJul 20, 2026
CVE-2026-13432MEDIUM5.4
  • image-sizes
NonOuiJul 20, 2026
CVE-2026-13156MEDIUM5.4
  • mailersend-official-smtp-integration
NonOuiJul 20, 2026
CVE-2026-8825MEDIUM4.9
  • elementor
NonOuiJul 20, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités