CVE-2026-28106 PUBLISHED

WordPress B2BKing Premium plugin <= 5.3.80 - Open Redirection vulnerability

Assigner: Patchstack
Reserved: 25.02.2026 Published: 06.03.2026 Updated: 06.03.2026

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kings Plugins B2BKing Premium allows Phishing.This issue affects B2BKing Premium: from n/a through 5.3.80.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
CVSS Score: 4.7

Product Status

Vendor Kings Plugins
Product B2BKing Premium
Versions Default: unaffected
  • affected from n/a to 5.3.80 (incl.)

Credits

  • 0xd4rk5id3 | Patchstack Bug Bounty Program finder

References

Problem Types

  • CWE-601 URL Redirection to Untrusted Site ('Open Redirect') CWE

Impacts

  • CAPEC-98 Phishing