Sceawere
Vulnerability Detail
CVE-2026-73396UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MWB HubSpot for WooCommerce Broken Authentication
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- MakeWebBetter
- Product
- MWB HubSpot for WooCommerce
- Attack Type
- CWE-288 Authentication Bypass Using an Alternate Path or Channel
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-08-18T15:17:06.963Z",
"pubdate": "2026-08-18T15:17:06.963Z",
"executiveSummary": "A broken authentication vulnerability has been identified in the MWB HubSpot for WooCommerce plugin affecting versions <= 1.6.7. This security flaw introduces severe risk implications by potentially allowing unauthorized users to bypass standard authentication mechanisms within the application context.\nThe vulnerability directly impacts the MWB HubSpot for WooCommerce product, exposing it to malicious manipulation by low-privileged or unauthenticated threat actors depending on the specific endpoint implementation.\nThe attacker capabilities include unauthorized access to sensitive functionalities or data streams typically restricted to higher privilege tiers, such as subscribers. Exploitation requirements involve network-based interaction with the vulnerable WordPress installation running the affected plugin versions.\nSuccessful exploitation of this broken authentication flaw can lead to unauthorized data exposure, privilege escalation scenarios, or state manipulation within the integrated HubSpot and WooCommerce ecosystems. Organizations utilizing the affected software versions face compromised confidentiality and integrity of their e-commerce infrastructure, necessitating immediate remediation actions to prevent exploitation by malicious actors.",
"technicalDetails": "The vulnerability resides in the MWB HubSpot for WooCommerce plugin, specifically affecting versions <= 1.6.7, where the authentication and authorization checks implemented within specific handlers or functions are either missing, improperly configured, or cryptographically weak.\nThe root cause stems from insufficient validation of user identity or session state during the processing of requests interacting with plugin-specific endpoints. This architectural flaw allows threat actors to interact directly with vulnerable components without supplying valid credentials or by leveraging predictable session parameters.\nThe vulnerable component involves the authentication routines handling subscriber-level or higher interactions within the plugin codebase. Due to inadequate access control enforcement, the application fails to adequately verify whether the incoming request originates from a legitimately authenticated entity possessing the requisite privileges.\nThe attack flow typically proceeds as follows: First, an attacker identifies the exposed plugin endpoints or AJAX handlers responsible for processing specific synchronization, data retrieval, or webhook functionalities associated with MWB HubSpot for WooCommerce. Second, the attacker crafts a malicious HTTP request targeting these endpoints, omitting valid authentication tokens or manipulating parameters designed to satisfy the weak validation checks. Third, upon receiving the crafted payload, the vulnerable component processes the request under the assumption of legitimate context, bypassing the intended security boundaries. Finally, the attacker achieves unauthorized execution of privileged logic, leading to data exfiltration, unauthorized modification of user records, or exposure of internal application states.\nThe exploitation method relies on network exposure, as the WordPress site hosting the vulnerable plugin is accessible via standard HTTP/HTTPS protocols. The attack requires low or no authentication requirements depending on the exact vector exposed by the broken access controls, allowing malicious actors to perform actions reserved for subscribers or administrative roles.\nThe post-exploitation impact includes unauthorized exposure of customer data synchronized between WooCommerce and HubSpot, potential compromise of connected API keys or webhook secrets, and general degradation of the hosting environment's security posture."
}