Executive brief
B2BKing is a WordPress plugin that manages B2B wholesale customer accounts and pricing in WooCommerce stores. The plugin fails to validate which roles users can select during self-registration, allowing attackers to bypass approval workflows and assign themselves to restricted wholesale customer groups without authentication. This allows unauthorized access to VIP pricing and wholesale features that should require manual approval.
Technical details
The vulnerability is an authorization bypass (CWE-862) in the registration form handler. The plugin accepts a role selection parameter during user registration but does not validate on the server side whether that role is actually offered on the registration form; it only enforces restrictions in the client-side HTML. An unauthenticated attacker can submit an arbitrary role identifier via the b2bking_registration_roles_dropdown parameter to assign themselves to any B2B customer group and bypass the manual approval workflow. The attack requires that WooCommerce self-registration and B2BKing role dropdown be enabled (default configuration), but no authentication or special preconditions. Affected versions are before 5.2.40; the fix is to validate role selections server-side.
Affected products
- B2BKing B2BKing before 5.2.40
Timeline
- 2026-09-04: disclosed
- 2026-09-06: patched: Fixed in version 5.2.40