
CVE-2026-1908 The Integration with Hubspot Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hubspotform' shortcode in all versions up to, and includin… https://www.cve.org/CVERecord?id=CVE-2026-1908
Post summary
The post discloses a stored XSS flaw in the Hubspot Forms WordPress plugin, highlighting how the issue can be triggered via the 'hubspotform' shortcode.
