CVE-2024-7389: Forminator <= 1.29.1 - HubSpot Developer API Key Sensitive Information Exposure
The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated attackers to extract the HubSpot integration developer API key and make unauthorized changes to the plugin's HubSpot integration or expose personally identifiable information from plugin users using the HubSpot integration.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7389?
CVE-2024-7389 is classified as a critical vulnerability due to its potential for sensitive information exposure.
How do I fix CVE-2024-7389?
To fix CVE-2024-7389, update the Forminator plugin to version 1.29.2 or later.
Who is affected by CVE-2024-7389?
All users of the Forminator plugin for WordPress running versions up to and including 1.29.1 are affected by CVE-2024-7389.
What type of vulnerability is CVE-2024-7389?
CVE-2024-7389 is a Sensitive Information Exposure vulnerability.
What information can be exposed due to CVE-2024-7389?
CVE-2024-7389 allows unauthenticated attackers to extract the HubSpot integration developer API key.