SQL Injection Vulnerability in LTL Freight Quotes Plugin for WordPress
CVE-2024-13477
9.8CRITICAL
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 12 February 2025
Summary
The LTL Freight Quotes – Unishippers Edition plugin for WordPress contains a vulnerability that allows unauthorized users to perform SQL Injection attacks. This occurs through inadequate escaping of the 'edit_id' parameter in all versions up to 2.5.8, enabling attackers to insert malicious SQL queries into the database query. Consequently, this vulnerability can lead to unauthorized access and retrieval of sensitive data stored in the database, posing serious risks to affected WordPress installations.
Affected Version(s)
LTL Freight Quotes – Unishippers Edition * <= 2.5.8
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Colin Xu