CVE-2026-85038: B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registration Role Selection
The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and to skip the manual account-approval workflow during self-registration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
B2BKing — Ultimate WooCommerce B2B and Wholesale Pluginto a version that resolves this vulnerability.Fixed in 5.2.40
Event History
Frequently Asked Questions
Does exploitation require an existing account or administrative access?
No. An unauthenticated user can exploit the issue during self-registration by selecting a role that is not actually offered on the registration form.
What controls can be bypassed through this issue?
An attacker can assign their account to restricted B2B customer groups and bypass the manual account-approval workflow.