CVE-2026-73396 HIGH

CVE-2026-73396: WordPress MWB HubSpot for WooCommerce plugin <= 1.6.7 - Broken Authentication vulnerability

Vendor Makewebbetter
Product MWB HubSpot for WooCommerce
Weakness CWE-288
Published August 18, 2026
Last update August 18, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

What the vulnerability does

01Description

Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.

Explanation of Vulnerability in Simple Terms

02Summary

MWB HubSpot for WooCommerce versions up to 1.6.7 contain an authentication bypass vulnerability. An attacker with low-level user access can bypass authentication checks through an alternate channel, allowing them to modify site data and disrupt service availability. Update to a version newer than 1.6.7 to resolve this issue.

What an attacker can do

03Attacker Capabilities

Bypass authentication to modify site data and cause service disruptions.

Potential impact on your site

04Site Impact

Authenticated users with low privileges can alter content and cause downtime without proper authorization.

Conditions required to exploit

05Prerequisites

Attacker must have low-level user account access to the site.

Key dates

06Disclosure timeline

August 18, 2026 CVE published
August 18, 2026 Record updated

Related vulnerabilities

08Related CVE