SQL Injection Vulnerability in bpost-shipping-platform Plugin for WordPress
CVE-2026-8082
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 21 July 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-8082?
The bpost-shipping-platform WordPress plugin, prior to version 3.2.3, is susceptible to a SQL injection vulnerability due to improper parameter sanitization during WooCommerce order processing. This flaw permits unauthenticated attackers to execute time-based blind SQL injection attacks, potentially compromising the database integrity of affected online stores.
Affected Version(s)
bpost-shipping-platform 0 < 3.2.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.