PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66589 Kings Plugins CVE debrief

The B2BKing plugin for WordPress has a Missing Authorization vulnerability, allowing for Exploiting Incorrectly Configured Access Control Security Levels. This issue affects versions from n/a through 5.2.30. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Organizations using the B2BKing plugin for WordPress should be aware of this vulnerability and take necessary actions to secure their installations. The CVE record was published on 2026-08-18T23:17:04.787Z and has not been modified since then. To address this vulnerability, organizations should verify their configurations and ensure proper authorization settings are in place.

Vendor
Kings Plugins
Product
B2BKing
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-21
Advisory published
2026-08-18
Advisory updated
2026-08-21

Who should care

Organizations using the B2BKing plugin for WordPress should be aware of this vulnerability and take necessary actions to secure their installations. This includes verifying configurations, ensuring proper authorization settings, and monitoring for unusual activity related to the B2BKing plugin. Security teams and vulnerability management teams should prioritize this vulnerability and plan for remediation.

Technical summary

The B2BKing plugin for WordPress has a Missing Authorization vulnerability, which allows for Exploiting Incorrectly Configured Access Control Security Levels. This issue affects versions from n/a through 5.2.30. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. To mitigate this vulnerability, organizations should verify their configurations and ensure proper authorization settings are in place.

Defensive priority

Organizations using B2BKing plugin for WordPress should verify their configurations and ensure proper authorization settings are in place.

Recommended defensive actions

  • Verify B2BKing plugin configurations to ensure proper authorization settings.
  • Update B2BKing plugin to a version beyond 5.2.30 if available.
  • Monitor for unusual activity related to the B2BKing plugin.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE-2026-66589 record indicates a Missing Authorization vulnerability in the B2BKing plugin for WordPress, allowing Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing from n/a through 5.2.30. The CVSS score is 5.4, with a severity of MEDIUM. The information is based on the official CVE record and NVD detail page.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T23:17:04.787Z and has not been modified since then.