LLM Hubspot Blog Import Missing Authorization Vulnerability on WordPress
Vulnerability
A vulnerability exists in the LLM Hubspot Blog Import plugin for WordPress, all versions through 1.0.1, due to a lack of proper capability checks on the 'process_save_blogs' AJAX endpoint. This flaw allows authenticated attackers with Subscriber-level access or higher to import all Hubspot data, unauthorized.
Impact
Exploitation of this vulnerability could lead to unauthorized data modification, allowing attackers to import Hubspot data without proper authorization.
Added: Oct 24, 2025, 9:33 AM
Updated: Oct 24, 2025, 9:33 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
5.2remediation
0.0relevance
0.8threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
