CVE-2024-10591: MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics <= 1.5.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Options Update
The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the hubwoosaveupdates() function in all versions up to, and including, 1.5.9. This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10591?
CVE-2024-10591 has been classified as a high severity vulnerability due to its potential for unauthorized modification of data and privilege escalation.
How do I fix CVE-2024-10591?
To mitigate CVE-2024-10591, update the MWB HubSpot for WooCommerce plugin to version 1.6.0 or later to ensure proper capability checks are in place.
What type of vulnerability is CVE-2024-10591?
CVE-2024-10591 is categorized as a privilege escalation vulnerability which arises from the lack of capability checks in the plugin.
Which versions of HubSpot for WooCommerce are affected by CVE-2024-10591?
CVE-2024-10591 affects MWB HubSpot for WooCommerce versions up to and including 1.5.9.
Who is the vendor associated with CVE-2024-10591?
The vendor associated with CVE-2024-10591 is MakeWebBetter, the developer of the HubSpot for WooCommerce plugin.