CVE-2026-66598: WordPress B2BKing Premium plugin <= 5.6.07 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress B2BKing Premium pluginto a version that resolves this vulnerability.Fixed in 5.6.08
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or other prior privileges. Exploitation still requires user interaction, as reflected by the UI:R vector.
Which installations are affected?
B2BKing Premium versions 5.6.07 and earlier are identified as affected. The provided information does not state whether a particular plugin configuration is required.
What impact can successful exploitation have?
The CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. The vulnerability type is cross-site scripting, meaning attacker-supplied script may execute in a user's browser after the required interaction.