
水野信太郎 🏅HubSpot×AI×Dataのことなら100へ|シニアコンサルタント@100shintaro_miz
Patch
HubSpotの公式WordPressプラグイン「All-In-One Marketing」にOAuthリフレッシュトークンが平文取得される脆弱性(CVE-2026-57736)。7/10公開のv11.3.65で修正済み。利用者は早めの更新を推奨します。 https://wordpress.org/plugins/leadin/ #HubSpot #セキュリティ
Post summary
CVE-2026-57736 in HubSpot's WordPress plugin allows plaintext capture of OAuth refresh tokens, but the issue was fixed in v11.3.65 released July 10; users are urged to update promptly.
11020141
153 followersView on X
