SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85038

MEDIUM · CVSS 5.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-06 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The B2BKing plugin for WordPress versions prior to 5.2.40 is vulnerable as it fails to validate user roles during the registration process, enabling unauthenticated users to self-assign themselves to restricted B2B customer groups. This oversight can lead to unauthorized access to sensitive B2B functionalities and bypassing of the manual account approval process. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-85038
Severity
MEDIUM
CVSS
5.3
EPSS
0.18%
WordPress

Original NVD Description

The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and to skip the manual account-approval workflow during self-registration.