What the vulnerability does
01Description
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
What the vulnerability does
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
Explanation of Vulnerability in Simple Terms
MWB HubSpot for WooCommerce versions up to 1.6.7 contain an authentication bypass vulnerability. An attacker with low-level user access can bypass authentication checks through an alternate channel, allowing them to modify site data and disrupt service availability. Update to a version newer than 1.6.7 to resolve this issue.
What an attacker can do
Bypass authentication to modify site data and cause service disruptions.
Potential impact on your site
Authenticated users with low privileges can alter content and cause downtime without proper authorization.
Conditions required to exploit
Attacker must have low-level user account access to the site.
Key dates
External resources
Related vulnerabilities