CyberRota Analysis
AI-GeneratedThe bpost-shipping-platform WordPress plugin prior to version 3.2.3 is vulnerable to time-based blind SQL injection due to inadequate parameter sanitization during WooCommerce order submissions. This flaw allows unauthenticated attackers to manipulate SQL queries, potentially compromising sensitive data within affected WordPress stores. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.
Original NVD Description
The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers to perform time-based blind SQL injection on stores running this bpost-shipping-platform WordPress plugin before 3.2.3.