Sensitive Information Exposure in HubSpot All-In-One Marketing Plugin for WordPress
CVE-2025-11762
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 April 2026
What is CVE-2025-11762?
The HubSpot All-In-One Marketing plugin for WordPress is vulnerable due to a flaw in the leadin/public/admin/class-adminconstants.php file. Authenticated attackers with Contributor-level access can exploit this vulnerability to access sensitive information, specifically a comprehensive list of all installed plugins and their respective versions. This information could be used for reconnaissance, potentially ensuring further attacks against the WordPress installation.
Affected Version(s)
HubSpot All-In-One Marketing β Forms, Popups, Live Chat 0 <= 11.3.32