PatchSiren cyber security CVE debrief
CVE-2026-66589 Kings Plugins CVE debrief
The B2BKing plugin for WordPress has a Missing Authorization vulnerability, allowing for Exploiting Incorrectly Configured Access Control Security Levels. This issue affects versions from n/a through 5.2.30. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Organizations using the B2BKing plugin for WordPress should be aware of this vulnerability and take necessary actions to secure their installations. The CVE record was published on 2026-08-18T23:17:04.787Z and has not been modified since then. To address this vulnerability, organizations should verify their configurations and ensure proper authorization settings are in place.
- Vendor
- Kings Plugins
- Product
- B2BKing
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-08-21
Who should care
Organizations using the B2BKing plugin for WordPress should be aware of this vulnerability and take necessary actions to secure their installations. This includes verifying configurations, ensuring proper authorization settings, and monitoring for unusual activity related to the B2BKing plugin. Security teams and vulnerability management teams should prioritize this vulnerability and plan for remediation.
Technical summary
The B2BKing plugin for WordPress has a Missing Authorization vulnerability, which allows for Exploiting Incorrectly Configured Access Control Security Levels. This issue affects versions from n/a through 5.2.30. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. To mitigate this vulnerability, organizations should verify their configurations and ensure proper authorization settings are in place.
Defensive priority
Organizations using B2BKing plugin for WordPress should verify their configurations and ensure proper authorization settings are in place.
Recommended defensive actions
- Verify B2BKing plugin configurations to ensure proper authorization settings.
- Update B2BKing plugin to a version beyond 5.2.30 if available.
- Monitor for unusual activity related to the B2BKing plugin.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE-2026-66589 record indicates a Missing Authorization vulnerability in the B2BKing plugin for WordPress, allowing Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing from n/a through 5.2.30. The CVSS score is 5.4, with a severity of MEDIUM. The information is based on the official CVE record and NVD detail page.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-66589 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-66589
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-66589 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66589
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.