CVE-2026-85038
B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registration Role Selection
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and to skip the manual account-approval workflow during self-registration.
| Vendor | unknown |
| Product | b2bking — ultimate woocommerce b2b and wholesale plugin — wholesale prices, bulk order form & more |
| Published | Sep 6, 2026 |
| Last Updated | Sep 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown b2bking — ultimate woocommerce b2b and wholesale plugin — wholesale prices, bulk order form & more
Be the first to know when new medium vulnerabilities affecting unknown b2bking — ultimate woocommerce b2b and wholesale plugin — wholesale prices, bulk order form & more are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More
0 < 5.2.40
References
Credits
Farid Narimanov WPScan