CVE-2026-82227: WordPress WPBulky plugin <= 1.2.2 - SQL Injection vulnerability
Published Aug 28, 2026
·Updated
Contributor SQL Injection in WPBulky <= 1.2.2 versions.
Affected Software
1 affected component
WordPress WPBulky plugin<=1.2.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPBulky pluginto a version that resolves this vulnerability.Fixed in 1.2.3
Event History
Aug 28, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated WordPress account?
Yes. The vulnerability is rated PR:L and is described as a contributor SQL injection issue, indicating that an attacker needs low-privileged access such as a Contributor account.
2
Is a site exposed to unauthenticated internet attackers?
The provided CVSS vector does not indicate unauthenticated exploitation: it requires low privileges. Sites that allow untrusted users to hold Contributor-level accounts are the most directly exposed.
3
What is the expected impact if the vulnerability is exploited?
The CVSS metrics indicate high confidentiality impact and low availability impact, with no integrity impact listed. The scope is marked changed.