CVE-2024-7389
The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated attackers to extract the HubSpot integration developer API key and make unauthorized changes to the plugin's HubSpot integration or expose personally identifiable information from plugin users using the HubSpot integration.
- Affected products
- Forminator
- Incsub Forminator
- < 1.29.2
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.7% (48th percentile)
- Weakness
- CWE-522
- NVD status
- Analyzed
- Published
- 2024-08-02
CVE-2024-7389 at NVD
No indexed exploits for CVE-2024-7389 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-7389 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.