THREAT OPS › Threat News › [NVD] CVE-2026-85038 (MEDIUM 5.3) — The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assig
[NVD] CVE-2026-85038 (MEDIUM 5.3) — The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assig
CVE-2026-85038 CVSS: 5.3 MEDIUM Published: 2026-09-06T07:16:43.530
The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and t
Indicators of compromise
- CVE-2026-85038cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85038