CVE-2026-57736

HIGH

WordPress HubSpot plugin <= 11.3.51 - Sensitive Data Exposure vulnerability

Title source: cna
STIX 2.1

Description

Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. This issue affects HubSpot: from n/a through 11.3.51.

Scores

CVSS v3 7.4
EPSS 0.0018
EPSS Percentile 7.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (1)
HubSpot/HubSpot < 11.3.51
Published Jul 01, 2026
Tracked Since Jul 01, 2026