The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and to skip the manual account-approval workflow during self-registration.
Metrics
Affected Vendors & Products
References
History
Sun, 06 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-285 |
Sun, 06 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Sun, 06 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-285 |
Sun, 06 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and to skip the manual account-approval workflow during self-registration. | |
| Title | B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registration Role Selection | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-09-06T06:00:04.787Z
Updated: 2026-09-06T10:44:10.785Z
Reserved: 2026-09-02T20:27:23.176Z
Link: CVE-2026-85038
Updated: 2026-09-06T10:39:48.407Z
Status : Deferred
Published: 2026-09-06T07:16:43.530
Modified: 2026-09-08T19:15:18.627
Link: CVE-2026-85038
No data.