SQL Injection Vulnerability in Worldwide Express Edition Plugin for WordPress
CVE-2024-13473
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 February 2025
What is CVE-2024-13473?
The Worldwide Express Edition plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit SQL injection risks through the 'dropship_edit_id' and 'edit_id' parameters. This flaw arises from inadequate escaping of user inputs and insufficient preparation of SQL queries. Attackers can manipulate existing queries, potentially gaining access to sensitive database information.
Affected Version(s)
LTL Freight Quotes – Worldwide Express Edition * <= 5.0.20