MakeWebBetter MWB HubSpot for WooCommerce
cpe:2.3:a:makewebbetter:hubspot_for_woocommerce:*:*:*:*:wordpress:*:*
- <= 1.5.9
A vulnerability in the MWB HubSpot for WooCommerce plugin, specifically in versions through 1.5.9, allows authenticated users with Contributor-level access and above to bypass authorization checks and modify arbitrary data. This could lead to privilege escalation by enabling these users to change the default role of new users to administrator, potentially giving them full administrative access on the site.
Exploitation of this vulnerability could allow an authenticated user to gain administrative privileges on the WordPress site.
Users are advised to update the MWB HubSpot for WooCommerce plugin to version 1.6.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.