Description
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MWB HubSpot for WooCommerce plugin for WordPress contains a broken authentication flaw that permits any user to log in as a subscriber without providing valid credentials. This weakness, identified as CWE‑288, means an attacker who can reach the vulnerable endpoints can gain authenticated access to the WordPress site and potentially exploit any features that are scoped to logged‑in users. The compromised credentials enable further actions that require subscriber‑level privileges, such as interacting with payment or customer data exposed through the plugin.

Affected Systems

WordPress installations that have the MakeWebBetter MWB HubSpot for WooCommerce plugin installed with a version of 1.6.7 or earlier are affected. All sites using these plugin versions, regardless of host or environment, are susceptible.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, indicating a high risk to confidentiality and integrity for affected sites. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, suggesting no documented large‑scale exploitation as of now. The attack vector is inferred to be remote, requiring only access to the WordPress front‑end because the flaw can be exercised by submitting crafted requests to the plugin’s authentication endpoints. Even though no public exploitation campaigns are known, the ability to bypass authentication warrants prompt remediation.

Generated by OpenCVE AI on August 18, 2026 at 16:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the MWB HubSpot for WooCommerce plugin to a version newer than 1.6.8.
  • If an upgrade cannot be applied immediately, disable or remove the plugin to eliminate the vulnerable functionality until a patch is released.
  • As a temporary containment measure, enforce stronger authentication on the WordPress site, such as enabling two‑factor authentication or setting a mandatory password policy, to limit the impact of unresolved authentication flaws.

Generated by OpenCVE AI on August 18, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Makewebbetter
Makewebbetter hubspot For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Makewebbetter
Makewebbetter hubspot For Woocommerce
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
Title WordPress MWB HubSpot for WooCommerce plugin <= 1.6.7 - Broken Authentication vulnerability
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Makewebbetter Hubspot For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T19:48:19.224Z

Reserved: 2026-08-12T14:10:14.732Z

Link: CVE-2026-73396

cve-icon Vulnrichment

Updated: 2026-08-18T19:39:12.761Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:17:06.963

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-73396

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:18:57Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel