B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More <= 5.2.30 - Missing Authorization
medium
The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.2.30. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with...
- CVSS:
- 4.3
- Affected:
- up to 5.2.30
- Fixed in:
- 5.2.40
- Disclosed:
- Aug 18, 2026
CVE-2026-66589 on NVD →
B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More < 5.2.10 - Missing Authorization
low
The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 5.2.10. This makes it possible for authenticated attackers, with shop manager-level access an...
- CVSS:
- 2.7
- Affected:
- up to 5.2.10
- Fixed in:
- 5.2.10
- Disclosed:
- May 25, 2026
CVE-2026-27346 on NVD →
B2BKing <= 4.6.00 - Missing Authorization to Authenticated(Subscriber+) Price Modification
medium
The B2BKing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'b2bking_save_price_import' function in versions up to, and including, 4.6.00. This makes it possible for Authenticated attackers with subscriber or customer-level permissions to modify the prici...
- CVSS:
- 6.5
- Affected:
- up to 4.6.00
- Fixed in:
- 4.6.20
- Disclosed:
- Jun 3, 2023
CVE-2023-3125 on NVD →
B2BKing <= 4.6.00 - Missing Authorization to Authenticated(Subscriber+) Information Disclosure
medium
The B2BKing plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'b2bkingdownloadpricelist' function in versions up to, and including, 4.6.00. This makes it possible for Authenticated attackers with subscriber or customer-level permissions to retrieve the full prici...
- CVSS:
- 4.3
- Affected:
- up to 4.6.00
- Fixed in:
- 4.6.20
- Disclosed:
- Jun 3, 2023
CVE-2023-3126 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database