Impact
Unverified role choices during registration allow unauthenticated users to assign themselves to restricted B2B customer groups and skip the manual approval process. The flaw enables these users to gain privileges or access that were meant to be granted only to approved customers, leading to potential privilege escalation and data exposure.
Affected Systems
The vulnerability affects installations of the B2BKing Ultimate WooCommerce B2B & Wholesale plugin for WordPress with a version older than 5.2.40. An attacker can exploit any site that has this plugin active and permits self‑registration of B2B customers.
Risk and Exploitability
Because the flaw is accessed via the public registration form and does not require authentication, the attack vector is likely a simple web request to the registration endpoint. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation data to date. However, the software’s ability to grant group membership without approval means that the risk depends on the sensitivity of the restricted groups; an attacker could obtain elevated permissions or sensitive customer information if those groups provide such access.
OpenCVE Enrichment