CVE-2026-9656

HubSpot All-In-One Marketing <= 11.3.62 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script

The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the site's plaintext HubSpot OAuth refresh token exposed via the window.leadinConfig JavaScript object, which can then be used to access or modify data in the connected HubSpot tenant. Although the refresh token is stored at rest with AES-256-CTR encryption, decryption occurs server-side before the plaintext value is passed to wp_localize_script(), rendering the at-rest encryption ineffective against this exposure path.


We have discovered 81,842 live websites that are affected by CVE-2026-9656.

Run a Free Instant Scan




Affected Software

Product  Leadin
Category Wordpress Plugins
Vulnerable Domains81,842 live websites (100% of Leadin install base)
Vulnerable Versions
  • from 0 through 11.3.62
Vulnerable Versions Count172 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Jul 17, 2026
  • Updated - Jul 17, 2026

Credits

  • anhcd05 (finder)

Website Distribution by Country

Number of websites using CVE-2026-9656
United States40,171 websites



GB5,276 websites
Germany4,766 websites
France3,662 websites
Australia2,588 websites
Canada2,319 websites
Netherlands1,806 websites
Spain1,737 websites
Italy1,535 websites
Brazil1,241 websites

Website Distribution by TLD

Number of websites using CVE-2026-9656
.com46,666 websites
.org3,246 websites
.co.uk3,092 websites
.com.au2,377 websites
.de2,075 websites
.net1,540 websites
.fr1,501 websites
.nl1,279 websites
.com.br1,144 websites
.ca1,122 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-9656

Top websites that are affected by CVE-2026-9656. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.org United States***
**********.de Germany***
****.com United States***
************.com United States*,***
***.domains Bulgaria*,***
************.com GB*,***
***.com United States*,***
*********.edu United States*,***
******.com United States*,***
*****.it France*,***
See full domain list

FAQ

CVE-2026-9656 is Exposure of Sensitive Information to an Unauthorized Actor in Leadin
A total of 81,842 websites have been identified as vulnerable to CVE-2026-9656, based on global website indexing conducted by WebTechSurvey.
The Leadin is affected by the CVE-2026-9656 vulnerability.
Leadin versions up to and including 11.3.62 are vulnerable to CVE-2026-9656.