HomeSecurityNew security flaw in WordPress B2BKing: CVE-2026-66589

New security flaw in WordPress B2BKing: CVE-2026-66589

A new privilege-checking vulnerability affects WordPress B2BKing, a plugin used in WooCommerce e-commerce stores for wholesale operations. The entry CVE-2026-66589 has a rating of 5.4 and is classified as moderate severity.

According to the CVE Alert, the issue is of the Missing Authorization type and is related to incorrectly configured access control levels. The description states that WordPress B2BKing versions up to 5.2.30 are affected.

See also: WPAdverts 2.3.3: Critical vulnerability in WordPress REST API

What does the vulnerability in WordPress B2BKing mean?

A Missing Authorization issue occurs when a feature does not properly check whether the user has the required permission before performing an action. In practice, the weakness can allow an account with a limited role to access features or data normally reserved for administrators.

B2BKing adds features for price lists, company accounts, customer groups and inter-company orders to WooCommerce. For this reason, proper role separation is of particular importance: an incorrect setting does not only affect an individual user, but can affect commercial data and the operation of the store.

The available listing does not describe a specific endpoint, function, or proven exploit scenario. It also does not indicate that the vulnerability is being actively exploited. Therefore, it should not be inferred that every installation is already compromised or that CVE-2026-66589 automatically leads to a full site takeover.

WordPress Access Control B2BKing

Which websites are affected?

CVE-2026-66589 affects WordPress B2BKing up to version 5.2.30, but the log does not give a clear minimum version or mention a fixed version. The plugin page on WordPress.org also does not, in its current form, provide a separate announcement for this issue.

This means that administrators should not rely on an arbitrary assumption about whether a fix has been installed. They need to check the exact version from the WordPress dashboard, monitor the updates tab, and seek confirmation from the developer before rolling back exposed functionality.

At the same time, a control of users and roles can limit the risk. Partner, customer and administrator accounts should only have the permissions they need, while old or inactive accounts should be deactivated.

Particular care is needed in stores where the add-on connects to other billing, inventory, or customer management tools. Granting too many permissions to an integration can amplify the impact of an authorization issue. Managers should document which services communicate with the store and limit connections that are not necessary.

Impact of the WordPress B2BKing vulnerability

See also: Forminator Forms: Critical vulnerability affects WordPress sites

What should administrators do?

Until clear guidance is published, the safest approach is to immediately inventory your WordPress B2BKing installations and check for an available update through a trusted channel. If a patch is not available, organizations can temporarily restrict wholesale functionality or implement stricter access rules after a compatibility check.

Administrators should also review logs for unusual logins, role changes, price list modifications, and actions from accounts that are no longer in use. This search does not in itself prove an exploit, but it can help identify an unexpected change.

The CVE-2026-66589 page on NVD does not yet provide additional technical details or a specific upgrade recommendation. Therefore, website owners should avoid unverified instructions and keep a backup before making any changes to the plugin or its settings.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Changes should be tested on a copy of the store first, as an upgrade may impact order flows or theme customizations. After applying them, roles should be re-checked and a test order should be placed from a restricted account to confirm that business functions remain available without excessive access.

The SecNews technical team points out that a moderate rating does not mean negligible risk for an online store. When an add-on handles corporate customers, prices, and orders, incorrect authorization can turn into a business problem, even without a full server takeover.

See also: W3 Total Cache XSS: Critical vulnerability in WordPress websites

Security measures for WordPress B2BKing

Until an official technical update is available, careful permissions management, log monitoring, and timely installation of a confirmed fix are the key mitigation measures.

Ecommerce teams should notify the store manager and record the plugin version so that the next announcement can be leveraged immediately. A documented response is preferable to hasty changes that may disrupt orders.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS