CVE-2026-57736
Deferred Deferred - Pending Action

Sensitive Data Exposure in HubSpot

Vulnerability report for CVE-2026-57736, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-01

Last updated on: 2026-07-01

Assigner: Patchstack

Description

Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. This issue affects HubSpot: from n/a through 11.3.51.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-01
Last Modified
2026-07-01
Generated
2026-07-02
AI Q&A
2026-07-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hubspot wordpress_hubspot_plugin to 11.3.51 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Compliance Impact

The vulnerability in the HubSpot WordPress plugin allows for the exposure of sensitive data to unauthorized parties. This type of sensitive data exposure can potentially lead to non-compliance with data protection regulations such as GDPR and HIPAA, which require the protection of personal and sensitive information.

Since the vulnerability enables retrieval of embedded sensitive data, organizations using affected versions of the plugin may risk unauthorized disclosure of protected information, which could result in regulatory penalties or breaches of compliance obligations.

Immediate remediation, such as updating the plugin or applying mitigations, is recommended to reduce the risk of sensitive data exposure and maintain compliance with relevant standards.

Executive Summary

CVE-2026-57736 is a vulnerability in the WordPress HubSpot Plugin (versions 11.3.51 and below) that allows an attacker to retrieve embedded sensitive data that should normally be restricted.

This vulnerability is classified as Sensitive Data Exposure and falls under the OWASP Top 10 category A3.

It has a CVSS score of 7.4, indicating a moderate severity where exploitation is unlikely but could allow malicious actors to view sensitive information accessible to regular users.

Impact Analysis

This vulnerability could allow a malicious actor to access sensitive information embedded in the data sent by the HubSpot plugin, which is normally restricted.

Such exposure of sensitive data could lead to further exploitation of other weaknesses in the system.

Although the severity is considered low, the impact includes potential loss of confidentiality and integrity of sensitive information.

Mitigation Strategies

Immediate action is recommended to mitigate this vulnerability since there is no official patch available as of the report date.

  • Update the WordPress HubSpot Plugin to a version higher than 11.3.51 once a patch is released.
  • Seek assistance from your hosting provider or a web developer to help secure your installation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57736. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart