Junglewise Threat Intelligence

CVE-2026-66598: B2BKing Premium unauthenticated cross-site scripting

CVE-2026-66598 · Severity: high · CVSS 7.1 · Published 2026-08-20

Executive brief

B2BKing Premium is a WordPress plugin that provides B2B e-commerce functionality for online stores. An unauthenticated cross-site scripting (XSS) vulnerability in versions 5.6.07 and earlier allows attackers to inject malicious scripts into the website that can steal visitor data, hijack user accounts, or redirect customers to fraudulent pages—without requiring authentication to exploit the flaw.

Technical details

The vulnerability is a stored or reflected cross-site scripting (XSS) flaw classified as an injection attack (OWASP A3). The affected B2BKing Premium plugin versions 5.6.07 and earlier fail to properly validate or sanitize user input, allowing unauthenticated attackers to inject arbitrary JavaScript code. While user interaction is required for successful exploitation (e.g., a victim must visit a malicious link or click on a crafted payload), the impact is significant: attackers can steal session cookies, capture sensitive data, or perform actions on behalf of legitimate users. The vulnerability has been patched in version 5.6.08 and later.

Affected products

  • B2BKing Premium <= 5.6.07

Timeline

  • 2026-08-20: disclosed
  • 2026-08-20: patched: Patched in version 5.6.08

References