SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-8082

HIGH · CVSS 7.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The bpost-shipping-platform WordPress plugin prior to version 3.2.3 is vulnerable to time-based blind SQL injection due to inadequate parameter sanitization during WooCommerce order submissions. This flaw allows unauthenticated attackers to manipulate SQL queries, potentially compromising sensitive data within affected WordPress stores. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-8082
Severity
HIGH
CVSS
7.5
EPSS
0.26%
WordPress

Original NVD Description

The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers to perform time-based blind SQL injection on stores running this bpost-shipping-platform WordPress plugin before 3.2.3.