CVE-2026-66589: WordPress B2BKing plugin <= 5.2.30 - Broken Access Control vulnerability
Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects B2BKing: from n/a through 5.2.30.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress B2BKing pluginto a version that resolves this vulnerability.Fixed in 5.2.40
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
Exploitation is network-reachable, requires low-level privileges, and does not require user interaction. The issue can affect confidentiality and integrity, while no availability impact is indicated.
Which versions are affected, and is a fixed release identified?
B2BKing versions through 5.2.30 are affected. The provided data does not identify a fixed version.
What is known about the affected access-control condition?
The vulnerability is described as missing authorization caused by incorrectly configured access-control security levels. The provided data does not specify affected endpoints, settings, detection steps, or a workaround when patching is unavailable.