Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-85038
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-85038 is an unauthenticated authorization bypass vulnerability in the B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin for WordPress. The flaw allows unauthenticated users to self-assign restricted B2B customer group roles during registration and bypass the manual account-approval workflow. All plugin versions before 5.2.40 are affected. It was publicly disclosed on September 4, 2026, with the CVE published on September 6, 2026. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (WPScan, GitHub Advisory).

Technical details

The root cause is a missing server-side authorization check (CWE-862) during the user registration process. The plugin fails to validate that the role submitted in the registration form corresponds to one of the roles actually offered on that form, meaning an attacker can manipulate the role parameter in the registration request to specify any restricted B2B customer group. No authentication, special privileges, or user interaction is required — the attack is fully network-accessible with low complexity. The vulnerability was discovered and reported by researcher Farid Narimanov; a proof-of-concept is scheduled for public release on September 18, 2026, to allow time for patching (WPScan).

Impact

Successful exploitation allows an unauthenticated attacker to register an account with unauthorized B2B customer group privileges, gaining access to wholesale pricing, bulk ordering features, and other restricted B2B functionality without administrator approval. The primary impact is an integrity violation — unauthorized modification of account role assignments — with no direct confidentiality or availability impact. This could result in financial harm to site operators through unauthorized access to wholesale discounts or restricted product catalogs (GitHub Advisory, WPScan).

Exploitability

No public proof-of-concept exploit is currently available, though WPScan has indicated one will be published on September 18, 2026. There is no evidence of in-the-wild exploitation at this time, and the CVE status is listed as "Deferred" with no CISA KEV catalog entry. The EPSS score is approximately 0.136–0.182%, placing it in a low exploitation probability tier. The attack is classified as automatable due to its network accessibility and lack of required authentication or user interaction (WPScan, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the B2BKing plugin (versions before 5.2.40) by inspecting page source, plugin-specific JavaScript/CSS paths, or using tools like WPScan to enumerate installed plugins.
  2. Locate registration endpoint: Navigate to the site's B2BKing-enabled registration page, which presents a role selection field for B2B customer group assignment.
  3. Intercept and manipulate the request: Using a proxy tool (e.g., Burp Suite), intercept the registration form submission and modify the role parameter to specify a restricted B2B customer group not offered on the visible form.
  4. Submit crafted registration: Send the manipulated request to the server; due to the missing server-side role validation, the plugin accepts the unauthorized role assignment.
  5. Bypass approval workflow: The attacker's newly created account is assigned to the restricted B2B group without triggering the manual administrator approval process, granting immediate access to wholesale pricing and restricted features (WPScan).

Indicators of compromise

  • Logs: WordPress registration logs or WooCommerce customer logs showing new accounts assigned to restricted B2B customer groups without a corresponding administrator approval action; unusual spikes in self-registration activity.
  • Database: User accounts in the WordPress wp_usermeta table with B2B group role assignments that were not processed through the standard approval workflow (e.g., accounts with restricted group roles but no approval timestamp or admin action record).
  • Application Behavior: New customer accounts accessing wholesale pricing pages, bulk order forms, or B2B-restricted product catalogs shortly after registration without admin approval.

Mitigation and workarounds

Site administrators should upgrade the B2BKing plugin to version 5.2.40 or later, which introduces proper server-side validation of role selections during registration. As an interim measure, administrators can disable self-registration on the site until the patch is applied. After patching, it is recommended to audit existing user accounts — particularly those registered before the fix — to identify any accounts with unauthorized B2B customer group assignments and remediate them manually (WPScan, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93031HIGH8.8
  • use-your-drive
NoYesSep 18, 2026
CVE-2026-87915HIGH7.2
  • popup-maker
NoYesSep 18, 2026
CVE-2026-18405HIGH7.2
  • jeg-elementor-kit
NoYesSep 18, 2026
CVE-2026-15797MEDIUM6.4
  • popup-maker
NoYesSep 18, 2026
CVE-2026-90884MEDIUM5.4
  • wp-recipe-maker
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management