CVE-2026-28106: WordPress B2BKing Premium plugin < 5.4.20 - Open Redirection vulnerability
Published Mar 6, 2026
·Updated
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kings Plugins B2BKing Premium allows Phishing.This issue affects B2BKing Premium: from n/a before 5.4.20.
Affected Software
1 affected component
Kings Plugins B2BKing Premium<5.4.20
Remediation
Information
Update the WordPress B2BKing Premium plugin to the latest available version (at least 5.4.20).
Event History
Mar 6, 2026
CVE Published
via MITRE·11:49 AM
Data Sourced
via MITRE·11:49 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-28106?
CVE-2026-28106 has been classified as a medium severity vulnerability due to its potential for phishing attacks.
2
How do I fix CVE-2026-28106?
To fix CVE-2026-28106, upgrade the B2BKing Premium plugin to version 5.3.81 or later.
3
What is the impact of CVE-2026-28106 on my WordPress site?
CVE-2026-28106 can allow attackers to redirect users to untrusted sites, potentially leading to phishing attempts.
4
Which versions of B2BKing Premium are affected by CVE-2026-28106?
CVE-2026-28106 affects all versions of B2BKing Premium up to and including 5.3.80.
5
Is there a patch available for CVE-2026-28106?
Yes, a patch is available by updating the B2BKing Premium plugin to version 5.3.81 or higher.