Sceawere

Vulnerability Detail

CVE-2026-87780UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LTL Freight Quotes Stored XSS

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
8h ago
Vendor
Unknown
Product
LTL Freight Quotes
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape values submitted through an unauthenticated endpoint before storing them and outputting them back in an administrative page, leading to Stored XSS which will execute in the session of any administrator viewing it.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-10T06:16:43.667Z",
  "pubdate": "2026-10-10T06:16:43.667Z",
  "executiveSummary": "The LTL Freight Quotes WordPress plugin, specifically versions prior to 4.2.19, contains a critical Stored Cross-Site Scripting (XSS) vulnerability. The flaw originates from the failure to properly sanitize and escape user-supplied data transmitted through an unauthenticated endpoint before it is persisted in the database.\nThis vulnerability allows an unauthenticated remote attacker to inject malicious JavaScript payloads into the application. The stored payload is subsequently executed within the security context of an administrator's browser session whenever they access the affected administrative dashboard.\nThe potential impact includes full administrative session hijacking, unauthorized configuration changes, potential redirection of site traffic, and the execution of arbitrary actions on behalf of the administrator. Given that the attack requires no authentication to initiate and targets high-privilege accounts, the risk profile is considered high. The vulnerability poses a significant threat to the integrity and confidentiality of the WordPress environment, as the administrative console serves as a central hub for site management.",
  "technicalDetails": "The vulnerability resides in the data handling logic of the LTL Freight Quotes plugin. The root cause is the lack of input sanitization and output encoding on data submitted via an unauthenticated endpoint. When a user submits data to this endpoint, the plugin directly stores the input into the database without validating or filtering the contents, effectively treating untrusted data as trusted strings.\nThe attack flow proceeds as follows: An unauthenticated attacker crafts a malicious request containing a payload, typically a JavaScript snippet encapsulated within HTML tags (e.g., <script>alert(document.cookie);</script>), and submits it to the vulnerable plugin endpoint. The plugin accepts this input and stores it persistently. Later, when an administrator navigates to the plugin's administrative interface, the backend retrieves this stored data and echoes it directly into the HTML response stream without proper context-aware output encoding (such as htmlspecialchars or esc_html).\nBecause the payload is rendered in the administrator's browser, the JavaScript executes within the authenticated session of the administrator. This grants the attacker access to the administrator's cookies, session tokens, and the ability to interact with the WordPress API via the administrative session. Consequently, an attacker can leverage this XSS to perform unauthorized administrative operations, such as creating new rogue user accounts, modifying plugin settings, or injecting further persistent malicious content into the site's frontend templates.\nThe vulnerability is restricted to versions prior to 4.2.19. Since the endpoint is accessible without authentication, it allows for easy remote exploitation. The attack is fully 'stored,' meaning the malicious script remains active until the record is deleted or sanitized. No specific interactions are required from the victim other than viewing the affected admin page, making this a passive but highly effective attack vector against site administrators."
}
CVE-2026-87780: LTL Freight Quotes Stored XSS (HIGH Severity, CVSS: 8.8) | Sceawere