
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-85038 is an unauthenticated authorization bypass vulnerability in the B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin for WordPress. The flaw allows unauthenticated users to self-assign restricted B2B customer group roles during registration and bypass the manual account-approval workflow. All plugin versions before 5.2.40 are affected. It was publicly disclosed on September 4, 2026, with the CVE published on September 6, 2026. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (WPScan, GitHub Advisory).
The root cause is a missing server-side authorization check (CWE-862) during the user registration process. The plugin fails to validate that the role submitted in the registration form corresponds to one of the roles actually offered on that form, meaning an attacker can manipulate the role parameter in the registration request to specify any restricted B2B customer group. No authentication, special privileges, or user interaction is required — the attack is fully network-accessible with low complexity. The vulnerability was discovered and reported by researcher Farid Narimanov; a proof-of-concept is scheduled for public release on September 18, 2026, to allow time for patching (WPScan).
Successful exploitation allows an unauthenticated attacker to register an account with unauthorized B2B customer group privileges, gaining access to wholesale pricing, bulk ordering features, and other restricted B2B functionality without administrator approval. The primary impact is an integrity violation — unauthorized modification of account role assignments — with no direct confidentiality or availability impact. This could result in financial harm to site operators through unauthorized access to wholesale discounts or restricted product catalogs (GitHub Advisory, WPScan).
No public proof-of-concept exploit is currently available, though WPScan has indicated one will be published on September 18, 2026. There is no evidence of in-the-wild exploitation at this time, and the CVE status is listed as "Deferred" with no CISA KEV catalog entry. The EPSS score is approximately 0.136–0.182%, placing it in a low exploitation probability tier. The attack is classified as automatable due to its network accessibility and lack of required authentication or user interaction (WPScan, GitHub Advisory).
wp_usermeta table with B2B group role assignments that were not processed through the standard approval workflow (e.g., accounts with restricted group roles but no approval timestamp or admin action record).Site administrators should upgrade the B2BKing plugin to version 5.2.40 or later, which introduces proper server-side validation of role selections during registration. As an interim measure, administrators can disable self-registration on the site until the patch is applied. After patching, it is recommended to audit existing user accounts — particularly those registered before the fix — to identify any accounts with unauthorized B2B customer group assignments and remediate them manually (WPScan, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."