Sceawere
Vulnerability Detail
CVE-2026-87781UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
LTL Freight Quotes SQL Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.6
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- LTL Freight Quotes
- Attack Type
- CWE-89 SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.6",
"pubDate": "2026-10-10T06:16:43.807Z",
"pubdate": "2026-10-10T06:16:43.807Z",
"executiveSummary": "The LTL Freight Quotes WordPress plugin contains a critical SQL injection vulnerability in versions prior to 4.2.19. This security flaw originates from the failure to properly sanitize and escape user-supplied input before incorporating it into database queries.\nThe vulnerability allows unauthenticated remote attackers to inject malicious SQL commands directly into the application's backend database. By manipulating these queries, an attacker can bypass security controls, view sensitive information, modify database records, or potentially achieve full administrative control over the underlying data.\nThis SQL injection flaw poses a significant risk to the confidentiality, integrity, and availability of the WordPress site. Given the lack of authentication requirements, the attack surface is exposed to any remote user capable of reaching the web server. Successful exploitation could lead to unauthorized data exfiltration or total compromise of the database management system.",
"technicalDetails": "The root cause of this vulnerability is improper neutralization of special elements used in an SQL command. In the LTL Freight Quotes plugin, specific request parameters are processed by the application's backend scripts without being passed through necessary sanitization or parameterization functions (such as the WordPress $wpdb->prepare() method).\nThe vulnerability is triggered when an attacker sends a crafted HTTP request containing malicious SQL syntax within the vulnerable parameter. Because the application logic fails to distinguish between data and executable code, the injected SQL commands are executed within the context of the database user configured for the WordPress site. This effectively allows an attacker to manipulate the structure of the intended query.\nThe exploitation flow typically begins with an unauthenticated user identifying the vulnerable input vector through traffic analysis. An attacker can use techniques such as UNION-based SQL injection to append unauthorized SELECT statements to the original query, or utilize blind SQL injection to infer database content through boolean-based or time-based observations. By iteratively testing responses from the server, an attacker can extract tables, column names, administrator credentials, and sensitive customer order data.\nBecause the plugin executes database queries with the privileges assigned to the WordPress database user, the post-exploitation impact is limited only by those privileges. In many standard configurations, this access provides sufficient scope to perform data dumping, modify existing site configuration tables, or insert malicious administrative accounts into the wp_users table, potentially leading to persistent site-wide compromise.\nThis vulnerability affects all versions of the LTL Freight Quotes plugin before 4.2.19. The attack is executable over the network via HTTP/HTTPS protocols without requiring any prior authentication or established session, making it a critical threat to public-facing WordPress instances."
}