PatchSiren

B2BKing CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review B2BKing CVE published 2026-09-06

CVE-2026-85038

The B2BKing plugin for WordPress has a vulnerability allowing unauthenticated users to assign themselves to restricted B2B customer groups and bypass manual account approval during self-registration. This issue arises from the plugin's failure to verify that a selected role during registration is actually offered on the registration form. The vulnerability impacts WordPress installations using the B2BKing [truncated]