Pending AI Enrichment

This vulnerability was recently detected via the live feed and has not yet been processed by Precogs AI's context enrichment engine. The data below represents raw telemetric data.

RAW NVD TELEMETRY

CVE-2026-66589

CVSS Base Score
5.4 MEDIUM
Primary Weakness
CWE-862
Published Date
Aug 18, 2026
Data Source
NVD API

Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing: from n/a through 5.2.30.

Related Vulnerabilitiesvia CWE-862

CVE-2026-340537.1 HIGH

Missing Authorization in OpenEMR AJAX endpoint 'handle_deletions.php' before 8.0.0.3. Allows any authenticated user to irreversibly delete procedure orders and specimens for any patient.

CWE-862
CVE-2026-42618.8 HIGH

The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.

CWE-862
CVE-2026-36515.3 MEDIUM

The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.

CWE-862
CVE-2026-36455.3 MEDIUM

The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.

CWE-862
CVE-2026-33355.3 MEDIUM

The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.

CWE-862
CVE-2026-29418.8 HIGH

The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in all versions up to, and including, 1.

CWE-862

Is your system affected?

Precogs AI detects CVE-2026-66589 in compiled binaries, LLMs, and application layers — even without source code access.