Role Validation Flaw in B2BKing Plugin for WooCommerce by WordPress
CVE-2026-85038

Currently unrated

Key Information:

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-85038?

The B2BKing plugin for WooCommerce, prior to version 5.2.40, contains a security flaw where it fails to verify if a selected user role during registration matches the roles provided on the registration form. This oversight allows unauthenticated users to assign themselves to restricted B2B customer groups, effectively bypassing the manual approval process that is normally in place for self-registration. This vulnerability poses significant risks to user management and data integrity, necessitating prompt updates to the affected plugin version.

Affected Version(s)

B2BKing β€” Ultimate WooCommerce B2B and Wholesale Plugin β€” Wholesale Prices, Bulk Order Form & More 0 < 5.2.40

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Farid Narimanov
WPScan
.