Impact
The enituretechnology LTL Freight Quotes – Worldwide Express Edition WordPress plugin contains an SQL injection flaw arising from improper neutralization of special characters in user‑supplied data. This weakness allows attackers to embed arbitrary SQL statements into queries, potentially enabling unauthorized access to, alteration of, or deletion of database records that may contain shipping or business data. The vulnerability is classified as CWE‑89.
Affected Systems
All installations of the enituretechnology LTL Freight Quotes – Worldwide Express Edition plugin for WordPress running versions that are <= 5.0.20 are affected. The vulnerability applies to any WordPress site that deploys the plugin in those versions.
Risk and Exploitability
The CVSS score of 9.3 signals critical severity, but the EPSS score of less than 1% indicates that exploitation of this flaw in the wild is currently considered unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through the plugin’s web interface, such as exposed input fields or administrative actions that submit data to the database without proper sanitization. No additional prerequisites beyond having the vulnerable plugin installed are mentioned.
OpenCVE Enrichment
EUVD