SQL Injection Vulnerability in LTL Freight Quotes – Worldwide Express Edition by Eniture Technology
CVE-2025-24664

9.3CRITICAL

Key Information:

Vendor
WordPress
Vendor
CVE Published:
27 January 2025

Summary

LTL Freight Quotes – Worldwide Express Edition by Eniture Technology has a vulnerability that allows for SQL Injection, which can be exploited to manipulate backend database commands. This security flaw affects versions from n/a through 5.0.20, posing potential risks to sensitive data integrity if not addressed promptly. It’s crucial for users of this software to apply security patches or updates to protect against unauthorized data access.

Affected Version(s)

LTL Freight Quotes – Worldwide Express Edition <= 5.0.20

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Colin Xu (Patchstack Alliance)
.