Description
WordPress Plugin B2BKing-Ultimate WooCommerce Wholesale and B2B Solution-Wholesale Order Form, Catalog Mode, Dynamic Pricing & More is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change the price of any product. WordPress Plugin B2BKing-Ultimate WooCommerce Wholesale and B2B Solution-Wholesale Order Form, Catalog Mode, Dynamic Pricing & More version 4.6.00 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.6.20 or latest
References
Related Vulnerabilities
WordPress Plugin Job Board by BestWebSoft Cross-Site Scripting (1.0.0)
SharePoint CVE-2020-1440 Vulnerability (CVE-2020-1440)
WordPress Plugin Calendar Cross-Site Scripting (1.3.7)
WordPress Plugin Price Commander for WooCommerce Security Bypass (1.2.2)
Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2024-38477)