Impact
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in enituretechnology LTL Freight Quotes – FreightQuote Edition plugin creates a classic SQL injection issue. The flaw allows malicious input to be concatenated directly into a SQL statement, bypassing any sanitization. If exploited, an attacker could read or modify data in the database used by the plugin. The weakness is a direct application of CWE-89. No explicit confirmation that the vulnerability can lead to higher‑level system compromise is included in the description.
Affected Systems
The enituretechnology LTL Freight Quotes – FreightQuote Edition plugin for WordPress, versions up through 2.3.11 inclusive. Any WordPress installation that uses a vulnerable version is affected. No other vendor products are listed.
Risk and Exploitability
The CVSS score of 9.3 places the issue in the critical severity range. The EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote via HTTP requests to the plugin’s endpoints; the attacker only needs the ability to submit crafted input to the site. Successful exploitation would give the attacker read or write capabilities on the database tables accessed by the plugin. No information about privilege escalation or site-level control is present in the CVE report.
OpenCVE Enrichment
EUVD