Unauthenticated PHP Object Injection in Integration for Contact Form 7 by HubSpot
CVE-2026-49763
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 June 2026
What is CVE-2026-49763?
This vulnerability occurs in the Integration for Contact Form 7 HubSpot plugin, allowing attackers to exploit unauthenticated PHP Object Injection. When using versions up to 1.3.7, improperly handled user inputs can lead to unauthorized actions on the WordPress site, putting sensitive data at risk. It is crucial for users to update to the latest version and implement security best practices to mitigate potential exploitation.
Affected Version(s)
Integration for Contact Form 7 HubSpot <= 1.3.7