CVE-2026-87780 PUBLISHED

LTL Freight Quotes – Old Dominion Edition < 4.2.19 - Unauthenticated Stored XSS via Shipping Rules

Assigner: WPScan
Reserved: 09.09.2026 Published: 10.10.2026 Updated: 10.10.2026

The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape values submitted through an unauthenticated endpoint before storing them and outputting them back in an administrative page, leading to Stored XSS which will execute in the session of any administrator viewing it.

Product Status

Vendor Unknown
Product LTL Freight Quotes
Versions Default: unaffected
  • affected from 0 to 4.2.19 (excl.)

Credits

  • achmad sonif finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE