Impact
Unverified role choices during registration allow unauthenticated users to assign themselves to restricted B2B customer groups and skip the manual approval process. The flaw enables these users to gain privileges or access that were intended only for approved customers, potentially enabling privilege escalation and exposure of sensitive data.
Affected Systems
The vulnerability affects installations of the B2BKing Ultimate WooCommerce B2B & Wholesale plugin for WordPress with a version older than 5.2.40. Any site that has this plugin active and permits self‑registration of B2B customers may be exploited.
Risk and Exploitability
Because the flaw is accessed via the public registration form and does not require authentication, the attack vector is likely a simple web request to the registration endpoint. The EPSS score is <1%, indicating a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation data to date. The CVSS score of 5.3 indicates medium severity, but the risk depends on the sensitivity of the restricted groups, as an attacker could obtain elevated permissions or sensitive customer information if those groups provide such access.
OpenCVE Enrichment