VYPR
Medium severity4.9NVD Advisory· Published May 25, 2026

CVE-2026-27346

CVE-2026-27346

Description

Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects B2BKing: from n/a before 5.2.10.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A missing authorization vulnerability in the B2BKing plugin allows unprivileged users to perform higher-privileged actions; fixed in version 5.2.10.

Vulnerability

The B2BKing plugin for WordPress (versions before 5.2.10) contains a Missing Authorization vulnerability. This is a broken access control issue where the plugin fails to properly check authorization, authentication, or nonce tokens in certain functions, allowing an unprivileged user to execute actions normally reserved for higher-privileged roles.

Exploitation

An attacker must be an unauthenticated or low-privileged user (e.g., subscriber) and needs network access to the WordPress site. By crafting specific requests to the vulnerable functions that lack the required authorization checks, an attacker can trigger actions that should require higher privileges.

Impact

Successful exploitation permits an attacker to perform unauthorized actions, potentially including accessing sensitive data or modifying settings, leading to a compromise of confidentiality or integrity. The vulnerability is rated with low severity and is unlikely to be actively exploited in the wild, but it could be used in mass-exploit campaigns.

Mitigation

The issue is fixed in B2BKing version 5.2.10, released by May 2026. Users should update to 5.2.10 or later immediately. Patchstack users can enable auto-update for vulnerable plugins. If immediate update is not possible, consult your hosting provider or web developer for assistance.

[1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.