SQL Injection Vulnerability in LTL Freight Quotes Plugin for WordPress
CVE-2024-13477

9.8CRITICAL

Key Information:

Vendor
WordPress
Vendor
CVE Published:
12 February 2025

Summary

The LTL Freight Quotes – Unishippers Edition plugin for WordPress contains a vulnerability that allows unauthorized users to perform SQL Injection attacks. This occurs through inadequate escaping of the 'edit_id' parameter in all versions up to 2.5.8, enabling attackers to insert malicious SQL queries into the database query. Consequently, this vulnerability can lead to unauthorized access and retrieval of sensitive data stored in the database, posing serious risks to affected WordPress installations.

Affected Version(s)

LTL Freight Quotes – Unishippers Edition * <= 2.5.8

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Colin Xu
.