WordPress · Bpost-Shipping-Platform · CVE-2026-8082
**Name of the Vulnerable Software and Affected Versions**
bpost-shipping-platform WordPress plugin versions prior to 3.2.3
**Description**
An issue exists during WooCommerce order submission where a parameter is not properly sanitized before being used in a SQL query. This allows unauthenticated attackers to perform time-based blind SQL injection, a technique used to extract information from a database by observing the time it takes for the server to respond to specific queries.
**Recommendations**
Update bpost-shipping-platform WordPress plugin to version 3.2.3 or later.