Patch
CVE-2024-7389
with vRx
Introduction
The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated attackers to extract the HubSpot integration developer API key and make unauthorized changes to the plugin's HubSpot integration or expose personally identifiable information from plugin users using the HubSpot integration.
Reference: https://github.com/advisories/GHSA-q46j-26g9-j9w4
Patching the target
kali@kali:~/vicarius/cve-2024-7389$ python3 detection.py --url http://127.0.0.1
[*] Started the scan...
[+] The WordPress instance seems to be vulnerable to CVE-2024-7389.
kali@kali:~/vicarius/cve-2024-7389$ sudo docker exec -it 8cc1a93dd9f2 bash
root@8cc1a93dd9f2:/var/www/html# bash /tmp/remediation.sh
Installing Forminator – Contact Form, Payment Form & Custom Form Builder (1.34.0)
Downloading installation package from https://downloads.wordpress.org/plugin/forminator.1.34.0.zip...
Using cached file '/root/.wp-cli/cache/plugin/forminator-1.34.0.zip'...
Unpacking the package...
Installing the plugin...
Removing the old version of the plugin...
Plugin updated successfully.
Success: Installed 1 of 1 plugins.
[+] WordPress instance successfully patched and protected from CVE-2024-7389!
root@8cc1a93dd9f2:/var/www/html#
exit
kali@kali:~/vicarius/cve-2024-7389$ python3 detection.py --url http://127.0.0.1
[*] Started the scan...
[-] The WordPress instance seems NOT to be vulnerable to CVE-2024-7389.
kali@kali:~/vicarius/cve-2024-7389$
Once the remediation script is executed successfully, the target is patched, as we can notice from the above output!
Read more
Read less
Patch faster and smarter
with vRx
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
More than 600 customers trust vRx:




Solution
Remediate faster with vRx
Patch Management
vRx automatically deploys patches across all systems, cutting patching time by 80%.
Scripting Engine
vRx’s scripting engine solves complex vulnerabilities, like log4j, with built-in or custom scripts.
Patchless Protection
vRx’s Patchless Protection secures vulnerable apps and reduces risk while maintaining functionality.

Automated Patching, Scripting, and more
Talk with our team to get a personal walkthrough
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.