CVE-2026-8082
Received Received - Intake

Time-Based Blind SQL Injection in bpost Shipping Platform WordPress Plugin

Vulnerability report for CVE-2026-8082, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: WPScan

Description

The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers to perform time-based blind SQL injection on stores running this bpost-shipping-platform WordPress plugin before 3.2.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-21
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bpost_shipping_platform wordpress_plugin to 3.2.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated SQL injection vulnerability in the Bpost Shipping Platform WordPress plugin versions before 3.2.3. During WooCommerce order submission, the plugin fails to sanitize the shipping_pickup_id parameter before using it in a SQL query, allowing attackers to perform time-based blind SQL injection attacks without authentication.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the bpost-shipping-platform plugin version prior to 3.2.3. You can verify the installed version via the WordPress admin panel under Plugins or by inspecting the plugin files. Additionally, monitor for unusual database query patterns or time delays during WooCommerce order submissions, which may indicate SQL injection attempts.

Impact Analysis

Attackers could exploit this to manipulate database queries, potentially accessing or altering sensitive data like customer information, orders, or payment details. Since it requires no authentication, any unauthenticated user could attempt attacks against vulnerable stores.

Compliance Impact

This vulnerability could lead to unauthorized data access or manipulation, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations may face compliance violations, fines, or legal consequences if customer or patient data is compromised through this flaw.

Mitigation Strategies

Immediately update the bpost-shipping-platform plugin to version 3.2.3 or later. If updating is not possible, consider disabling the plugin temporarily until a patch is applied. Ensure your WordPress core, themes, and other plugins are also updated to their latest versions to reduce attack surfaces.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8082. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart