HubSpot All-In-One Marketing Plugin Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability allowing sensitive information exposure exists in the HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress, affecting all versions through 11.3.32. The issue arises in the leadin/public/admin/class-adminconstants.php file, where authenticated attackers with Contributor-level access or higher can access a list of all installed plugins and their versions. This information could be used for reconnaissance and to facilitate further attacks.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information about installed plugins, potentially allowing for targeted attacks based on the versions and types of plugins identified.

Remediation

Users can update to version 11.3.33 or a newer patched version to address this vulnerability.

Added: Apr 24, 2026, 8:22 AM
Updated: Apr 24, 2026, 8:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.9
remediation
0.0
relevance
6.6
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.