TROYANOSYVIRUS
Back to CVEs

CVE-2024-10591

HIGH
8.8

Description

The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the hubwoo_save_updates() function in all versions up to, and including, 1.5.9. This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVE Details

CVSS v3.1 Score8.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published1/30/2025
Last Modified4/8/2026
Sourcenvd
Honeypot Sightings0

Affected Products

makewebbetter:hubspot_for_woocommerce

Weaknesses (CWE)

CWE-862

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.