
PEACH
Un cadre d’isolation des locataires
CVE-2026-9656 is a Sensitive Information Exposure vulnerability in the HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress, classified as CWE-200. All versions up to and including 11.3.62 are affected. The flaw allows authenticated attackers with contributor-level access or above to extract the site's plaintext HubSpot OAuth refresh token exposed via the window.leadinConfig JavaScript object. It was published on July 17, 2026, with a patch available in version 11.3.64. The CVSS v3.1 base score is 4.3 (Medium) (GitHub Advisory).
The root cause is improper exposure of sensitive credentials to client-side JavaScript (CWE-200). Although the HubSpot OAuth refresh token is stored at rest using AES-256-CTR encryption, the plugin decrypts the token server-side and passes the plaintext value to WordPress's wp_localize_script() function, which embeds it in the page's JavaScript as part of the window.leadinConfig object. This renders the at-rest encryption entirely ineffective against this exposure path. Relevant code paths have been identified in class-adminconstants.php, class-gutenberg.php, class-oauth.php, and class-assetsmanager.php of the plugin (GitHub Advisory, Wordfence).
Successful exploitation allows an authenticated attacker with contributor-level WordPress access to obtain the plaintext HubSpot OAuth refresh token, which can then be used to access or modify data within the connected HubSpot tenant. This creates a risk of unauthorized data exfiltration, manipulation of marketing data, contact records, or other HubSpot-managed assets. There is no direct availability or integrity impact on the WordPress site itself, but the compromise of the HubSpot tenant could have significant downstream business consequences (GitHub Advisory).
window.leadinConfig object, which is injected by wp_localize_script().window.leadinConfig object in the page's JavaScript.api.hubapi.com) originating from IP addresses not associated with the WordPress server or known administrators.Update the HubSpot All-In-One Marketing plugin to version 11.3.64 or later, which addresses this exposure (changeset available between tags 11.3.62 and 11.3.64) (GitHub Advisory). As an interim measure, restrict contributor-level and above WordPress user access to only trusted personnel. If unauthorized access is suspected, revoke the exposed HubSpot OAuth refresh token from the HubSpot application settings and re-authorize the integration. Monitor the HubSpot tenant for unauthorized access or unexpected data changes.
The vulnerability was reported through Wordfence's threat intelligence platform and published to the GitHub Advisory Database on July 17, 2026 (Wordfence, GitHub Advisory). No significant broader media coverage or notable researcher commentary beyond the initial advisory has been observed at this time.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."