Description
The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and to skip the manual account-approval workflow during self-registration.
Published: 2026-09-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Role Assignment and Approval Bypass
Action: Update Plugin
AI Analysis

Impact

Unverified role choices during registration allow unauthenticated users to assign themselves to restricted B2B customer groups and skip the manual approval process. The flaw enables these users to gain privileges or access that were intended only for approved customers, potentially enabling privilege escalation and exposure of sensitive data.

Affected Systems

The vulnerability affects installations of the B2BKing Ultimate WooCommerce B2B & Wholesale plugin for WordPress with a version older than 5.2.40. Any site that has this plugin active and permits self‑registration of B2B customers may be exploited.

Risk and Exploitability

Because the flaw is accessed via the public registration form and does not require authentication, the attack vector is likely a simple web request to the registration endpoint. The EPSS score is <1%, indicating a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation data to date. The CVSS score of 5.3 indicates medium severity, but the risk depends on the sensitivity of the restricted groups, as an attacker could obtain elevated permissions or sensitive customer information if those groups provide such access.

Generated by OpenCVE AI on September 6, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade B2BKing to version 5.2.40 or later to enforce proper role validation.
  • Configure the registration form to expose only the intended role options and eliminate hidden or legacy role parameters.
  • Implement server‑side verification that the selected role is among the allowed set, following the proper authorization control guidance.
  • Audit newly created accounts for inappropriate group membership and revoke any that have been erroneously assigned.

Generated by OpenCVE AI on September 6, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 06 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285

Sun, 06 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 06 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285

Sun, 06 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and to skip the manual account-approval workflow during self-registration.
Title B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registration Role Selection
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-06T10:44:10.785Z

Reserved: 2026-09-02T20:27:23.176Z

Link: CVE-2026-85038

cve-icon Vulnrichment

Updated: 2026-09-06T10:39:48.407Z

cve-icon NVD

Status : Deferred

Published: 2026-09-06T07:16:43.530

Modified: 2026-09-08T19:15:18.627

Link: CVE-2026-85038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-06T15:30:05Z

Weaknesses