Impact
An unauthenticated attacker can exploit a time‑based blind SQL injection flaw in the bpost‑shipping‑platform WordPress plugin for WooCommerce sites. The plugin, when processing order submissions, fails to sanitize a user‑supplied parameter before incorporating it into a SQL query. This flaw allows an attacker to obtain or modify database contents without authentication, potentially exposing sensitive order data and customer information.
Affected Systems
The vulnerability is present in the bpost‑shipping‑platform WordPress plugin for e‑commerce sites running WooCommerce. Any installation of the plugin with a version earlier than 3.2.3 is affected. The plugin is used on WordPress‑based online stores that rely on bpost for shipping calculations.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑impact vulnerability that can lead to data tampering or disclosure. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the issue is not listed in the CISA KEV catalog. The attack vector appears to be a web‑based, unauthenticated vector that requires an attacker to submit a crafted order request via WooCommerce. Successful exploitation would allow the attacker to read or alter the database contents associated with the site.
OpenCVE Enrichment