Impact
The B2BKing WordPress plugin contains a missing authorization flaw that lets users with incorrectly granted access rights perform actions that should be protected. This can expose confidential wholesale pricing, order data, and potentially alter or delete it. The vulnerability is a classic example of improper authorization (CWE‑862).
Affected Systems
Kings Plugins B2BKing plugin versions up to 5.2.30 installed on WordPress sites are affected. All installations of the plugin older than 5.2.40 are vulnerable, including any earlier releases where the access controls were not fully enforced.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score is not available, so the likelihood of exploitation cannot be precisely quantified. The flaw is not listed in the CISA KEV catalog. Attackers would typically exploit the vulnerability by sending crafted requests to the plugin’s admin URLs from a web browser or automated tool, leveraging the lack of role validation to gain privileged access.
OpenCVE Enrichment