Impact
The MWB HubSpot for WooCommerce plugin for WordPress contains a broken authentication flaw that permits any user to log in as a subscriber without providing valid credentials. This weakness, identified as CWE‑288, means an attacker who can reach the vulnerable endpoints can gain authenticated access to the WordPress site and potentially exploit any features that are scoped to logged‑in users. The compromised credentials enable further actions that require subscriber‑level privileges, such as interacting with payment or customer data exposed through the plugin.
Affected Systems
WordPress installations that have the MakeWebBetter MWB HubSpot for WooCommerce plugin installed with a version of 1.6.7 or earlier are affected. All sites using these plugin versions, regardless of host or environment, are susceptible.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating a high risk to confidentiality and integrity for affected sites. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, suggesting no documented large‑scale exploitation as of now. The attack vector is inferred to be remote, requiring only access to the WordPress front‑end because the flaw can be exercised by submitting crafted requests to the plugin’s authentication endpoints. Even though no public exploitation campaigns are known, the ability to bypass authentication warrants prompt remediation.
OpenCVE Enrichment