plugin

B2Bking Wholesale For Woocommerce Vulnerabilities

4 known security issues reported for the B2Bking Wholesale For Woocommerce WordPress plugin. Most recent disclosed Aug 18, 2026.

3 medium 1 low

Running B2Bking Wholesale For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More <= 5.2.30 - Missing Authorization

medium

The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.2.30. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with...

CVSS:
4.3
Affected:
up to 5.2.30
Fixed in:
5.2.40
Disclosed:
Aug 18, 2026

CVE-2026-66589 on NVD →

B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More < 5.2.10 - Missing Authorization

low

The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 5.2.10. This makes it possible for authenticated attackers, with shop manager-level access an...

CVSS:
2.7
Affected:
up to 5.2.10
Fixed in:
5.2.10
Disclosed:
May 25, 2026

CVE-2026-27346 on NVD →

B2BKing <= 4.6.00 - Missing Authorization to Authenticated(Subscriber+) Price Modification

medium

The B2BKing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'b2bking_save_price_import' function in versions up to, and including, 4.6.00. This makes it possible for Authenticated attackers with subscriber or customer-level permissions to modify the prici...

CVSS:
6.5
Affected:
up to 4.6.00
Fixed in:
4.6.20
Disclosed:
Jun 3, 2023

CVE-2023-3125 on NVD →

B2BKing <= 4.6.00 - Missing Authorization to Authenticated(Subscriber+) Information Disclosure

medium

The B2BKing plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'b2bkingdownloadpricelist' function in versions up to, and including, 4.6.00. This makes it possible for Authenticated attackers with subscriber or customer-level permissions to retrieve the full prici...

CVSS:
4.3
Affected:
up to 4.6.00
Fixed in:
4.6.20
Disclosed:
Jun 3, 2023

CVE-2023-3126 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database