🔐 CVE Alert

CVE-2026-85038

MEDIUM 5.3

B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registration Role Selection

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and to skip the manual account-approval workflow during self-registration.

Vendor unknown
Product b2bking — ultimate woocommerce b2b and wholesale plugin — wholesale prices, bulk order form & more
Published Sep 6, 2026
Last Updated Sep 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown b2bking — ultimate woocommerce b2b and wholesale plugin — wholesale prices, bulk order form & more

Be the first to know when new medium vulnerabilities affecting unknown b2bking — ultimate woocommerce b2b and wholesale plugin — wholesale prices, bulk order form & more are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More
0 < 5.2.40

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/a397aeaf-7629-45dd-a2ee-3e904cc19550/

Credits

Farid Narimanov WPScan