Loading HuntDB...

GHSA-q46j-26g9-j9w4

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated attackers to extract the HubSpot integration developer API key and make unauthorized changes to the plugin's HubSpot integration or expose personally identifiable information from plugin users using the HubSpot integration.

Related CVEs

Key Information

GHSA ID
GHSA-q46j-26g9-j9w4
Published
August 2, 2024 6:30 AM
Last Modified
February 5, 2025 3:32 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 14, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.