CVE-2026-87781 PUBLISHED

LTL Freight Quotes – Old Dominion Edition 4.2.11 - 4.2.18 - Unauthenticated SQLi via Shipping Rule 'edit_id' Parameter

Assigner: WPScan
Reserved: 09.09.2026 Published: 10.10.2026 Updated: 10.10.2026

The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

Product Status

Vendor Unknown
Product LTL Freight Quotes
Versions Default: unaffected
  • affected from 4.2.11 to 4.2.19 (excl.)

Credits

  • achmad sonif finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE