CVE-2026-82227
—Contributor-Level SQL Injection in WPBulky WordPress Plugin (1.2.2 and Below)
WPBulky, a WordPress plugin, contains an SQL injection vulnerability (CWE-89) in all versions up to and including 1.2.2, caused by insufficiently sanitized user input being incorporated into a database query. The flaw is triggered by an authenticated user holding at least Contributor-level privileges, consistent with the 'Contributor' designation and the low-privilege requirement (PR:L) in the CVSS vector, who submits crafted input through the plugin's functionality. A successful attacker primarily gains unauthorized access to database content — the CVSS scoring indicates a high confidentiality impact with changed scope (S:C), meaning data beyond the attacker's own records may be readable — along with a low availability impact. Any WordPress site running WPBulky 1.2.2 or earlier that grants Contributor or higher roles access to the plugin is affected. Exploitation status is quiet: there is no public proof-of-concept, the CVE is not in CISA KEV, and EPSS currently estimates only a 0.2% probability of exploitation within the next 30 days.
What to do: Sites running WPBulky 1.2.2 or earlier should update to the latest patched release (any version above 1.2.2) as soon as it is available, and in the meantime restrict use of the plugin to trusted roles and review which Contributor-level accounts exist. Administrators should also confirm whether the plugin is installed, monitor database and web logs for anomalous queries, and consider web application firewall rules that block common SQL injection patterns.
| WPBulky WordPress plugin | <= 1.2.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Contributor SQL Injection in WPBulky <= 1.2.2 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.