PatchSiren cyber security CVE debrief
CVE-2026-66589 Kings Plugins CVE debrief
The B2BKing plugin for WordPress has a Missing Authorization vulnerability, allowing for Exploiting Incorrectly Configured Access Control Security Levels. This issue affects versions from n/a through 5.2.30. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Organizations using the B2BKing plugin for WordPress should be aware of this vulnerability and take necessary actions to secure their installations. The CVE record was published on 2026-08-18T23:17:04.787Z and has not been modified since then. To address this vulnerability, organizations should verify their configurations and ensure proper authorization settings are in place.
- Vendor
- Kings Plugins
- Product
- B2BKing
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-08-21
Who should care
Organizations using the B2BKing plugin for WordPress should be aware of this vulnerability and take necessary actions to secure their installations. This includes verifying configurations, ensuring proper authorization settings, and monitoring for unusual activity related to the B2BKing plugin. Security teams and vulnerability management teams should prioritize this vulnerability and plan for remediation.
Technical summary
The B2BKing plugin for WordPress has a Missing Authorization vulnerability, which allows for Exploiting Incorrectly Configured Access Control Security Levels. This issue affects versions from n/a through 5.2.30. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. To mitigate this vulnerability, organizations should verify their configurations and ensure proper authorization settings are in place.
Defensive priority
Organizations using B2BKing plugin for WordPress should verify their configurations and ensure proper authorization settings are in place.
Recommended defensive actions
- Verify B2BKing plugin configurations to ensure proper authorization settings.
- Update B2BKing plugin to a version beyond 5.2.30 if available.
- Monitor for unusual activity related to the B2BKing plugin.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE-2026-66589 record indicates a Missing Authorization vulnerability in the B2BKing plugin for WordPress, allowing Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing from n/a through 5.2.30. The CVSS score is 5.4, with a severity of MEDIUM. The information is based on the official CVE record and NVD detail page.
Official resources
-
CVE-2026-66589 CVE record
CVE.org
-
CVE-2026-66589 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T23:17:04.787Z and has not been modified since then.