WordPress Plugin Vulnerabilities

Bpost Shipping Platform < 3.2.3 - Unauthenticated SQL Injection

Description

The plugin does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers to perform time-based blind SQL injection on stores running this plugin.

Proof of Concept

Affects Plugins

References

Classification

Type
SQLI
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
bapcorn
Submitter
bapcorn
Verified
Yes

Timeline

Publicly Published
2026-06-30 (about 22 days ago)
Added
2026-06-30 (about 22 days ago)
Last Updated
2026-07-20 (about 1 day ago)

Other