CVE-2026-24559
Awaiting Analysis Awaiting Analysis - Queue
BaseFortify

Publication date: 2026-01-23

Last updated on: 2026-04-28

Assigner: Patchstack

Description
Insertion of Sensitive Information Into Sent Data vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Retrieve Embedded Sensitive Data.This issue affects Integration for Contact Form 7 HubSpot: from n/a through <= 1.4.3.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-23
Last Modified
2026-04-28
Generated
2026-06-16
AI Q&A
2026-01-23
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
patchstack integration_for_contact_form_7_hubspot to 1.4.3 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

This vulnerability involves the exposure of sensitive data, which could lead to non-compliance with data protection regulations such as GDPR and HIPAA that require safeguarding sensitive information. Unauthorized access to sensitive data may result in violations of these standards, potentially leading to legal and regulatory consequences. However, specific impacts on compliance are not detailed in the provided resources. [1]

Executive Summary

This vulnerability in the Integration for Contact Form 7 HubSpot plugin (versions up to 1.4.3) allows a malicious actor with subscriber or developer privileges to access sensitive information that should normally be restricted. It is classified as Sensitive Data Exposure under the OWASP Top 10 (A3). Although the severity is low (CVSS score 5.3), it can lead to unauthorized retrieval of embedded sensitive data. [1]

Impact Analysis

The vulnerability can lead to exposure of sensitive information to unauthorized users, which may enable further exploitation of other system weaknesses. While the likelihood of exploitation is low, the impact involves potential data breaches and unauthorized data access within the affected plugin environment. [1]

Detection Guidance

There are no specific detection commands or network indicators provided for this vulnerability. Detection would likely involve checking the version of the Integration for Contact Form 7 HubSpot plugin installed on your WordPress site to see if it is version 1.4.3 or earlier, as these versions are vulnerable. [1]

Mitigation Strategies

Since no official fix or patched version is currently available, immediate mitigation steps include limiting access to the plugin to trusted users only, monitoring for suspicious activity, and applying any recommended mitigation solutions or security intelligence provided by Patchstack to protect affected installations. [1]

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-24559. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart