What is CVE-2026-66589?
CVE-2026-66589 is a "Missing Authorization" vulnerability in the Kings Plugins B2BKing plugin that allows attackers to exploit incorrectly configured access control security levels. The issue impacts all versions of B2BKing from n/a through 5.2.30. Users are urged to update to the latest patched version immediately to mitigate the risk.
Azərbaycanca: CVE-2026-66589, Kings Plugins-in B2BKing plaginində aşkar edilmiş, yanlış konfiqurasiya olunmuş giriş nəzarəti səviyyələrindən istifadə edərək icazəsiz əməliyyatlar aparmağa imkan verən "Missing Authorization" zəifliyidir. Bu boşluq 5.2.30 daxil olmaqla bütün əvvəlki versiyalara təsir göstərir. İstifadəçilər öz saytlarını qorumaq üçün dərhal ən son plagın versiyasına yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin and versions are affected by the CVE-2026-66589 vulnerability?
CVE-2026-66589 affects the Kings Plugins B2BKing plugin, impacting all versions up to and including 5.2.30.
What should users do to protect against the CVE-2026-66589 vulnerability?
Users should immediately update the B2BKing plugin to the latest patched version to secure their websites.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.