SQL Injection Vulnerability in LTL Freight Quotes – Worldwide Express Edition by Eniture Technology
CVE-2025-24664
9.3CRITICAL
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 27 January 2025
Summary
LTL Freight Quotes – Worldwide Express Edition by Eniture Technology has a vulnerability that allows for SQL Injection, which can be exploited to manipulate backend database commands. This security flaw affects versions from n/a through 5.0.20, posing potential risks to sensitive data integrity if not addressed promptly. It’s crucial for users of this software to apply security patches or updates to protect against unauthorized data access.
Affected Version(s)
LTL Freight Quotes – Worldwide Express Edition <= 5.0.20
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Colin Xu (Patchstack Alliance)