SQL Injection Vulnerability in LTL Freight Quotes Plugin for WordPress
CVE-2024-13477
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 February 2025
What is CVE-2024-13477?
The LTL Freight Quotes – Unishippers Edition plugin for WordPress contains a vulnerability that allows unauthorized users to perform SQL Injection attacks. This occurs through inadequate escaping of the 'edit_id' parameter in all versions up to 2.5.8, enabling attackers to insert malicious SQL queries into the database query. Consequently, this vulnerability can lead to unauthorized access and retrieval of sensitive data stored in the database, posing serious risks to affected WordPress installations.
Affected Version(s)
LTL Freight Quotes – Unishippers Edition * <= 2.5.8