CVE-2026-8082 PUBLISHED

Bpost Shipping Platform < 3.2.3 - Unauthenticated SQL Injection

Assigner: WPScan
Reserved: 07.05.2026 Published: 21.07.2026 Updated: 21.07.2026

The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers to perform time-based blind SQL injection on stores running this bpost-shipping-platform WordPress plugin before 3.2.3.

Product Status

Vendor Unknown
Product bpost-shipping-platform
Versions Default: unaffected
  • affected from 0 to 3.2.3 (excl.)

Credits

  • bapcorn finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE