CVE-2026-73396: WordPress MWB HubSpot for WooCommerce plugin <= 1.6.7 - Broken Authentication vulnerability
Published Aug 18, 2026
·Updated
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
Affected Software
1 affected component
WordPress MWB HubSpot for WooCommerce<=1.6.7
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs low-level privileges, such as a subscriber account, and can exploit the issue remotely without user interaction. The CVSS vector indicates low attack complexity.
2
How can I tell whether my site is affected?
Sites using MWB HubSpot for WooCommerce version 1.6.7 or earlier are affected. Check the installed plugin version to determine whether the site falls within the affected range.