PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3646 enituretechnology CVE debrief

The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin's webhook handler in all versions up to, and including, 3.3.13. This is due to missing authentication, authorization, and nonce verification on a standalone PHP file that directly processes GET parameters and updates WordPress options. This vulnerability allows unauthenticated attackers to modify the plugin's subscription plan settings, effectively downgrading the store from a paid plan to the Trial Plan, changing the store type, and manipulating subscription expiration dates, potentially disabling premium features such as Dropship and Hazardous Material handling. Users should review their current subscription plans and monitor for unauthorized changes.

Vendor
enituretechnology
Product
LTL Freight Quotes – R+L Carriers Edition
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of the LTL Freight Quotes – R+L Carriers Edition plugin for WordPress should be aware of this vulnerability, as it allows unauthenticated attackers to modify the plugin's subscription plan settings. Affected operators, platform administrators, vulnerability management teams, and security teams should review their current subscription plans and monitor for unauthorized changes.

Technical summary

The vulnerability exists due to missing authentication, authorization, and nonce verification on a standalone PHP file that directly processes GET parameters and updates WordPress options. This makes it possible for unauthenticated attackers to modify the plugin's subscription plan settings, effectively downgrading the store from a paid plan to the Trial Plan, changing the store type, and manipulating subscription expiration dates. The CVSS score of 5.3 indicates a medium severity vulnerability.

Defensive priority

Medium priority given the CVSS score of 5.3 and the potential impact on subscription plan settings. Implement additional security measures to prevent unauthorized access to WordPress options and monitor subscription plan settings for unauthorized changes. Consider compensating controls for exposed systems while remediation is scheduled and verified. Review relevant monitoring, detection, and logs for exposed assets that need extra review. Track exceptions, retest remediated assets, and close the item only after evidence is documented. Update the LTL Freight Quotes – R+L Carriers Edition plugin to a version that includes a fix for this vulnerability. Perform an asset inventory to identify potentially affected systems. Implement rollback/change windows for updates. Track source references for additional information.

Recommended defensive actions

  • Update the LTL Freight Quotes – R+L Carriers Edition plugin to a version that includes a fix for this vulnerability.
  • Monitor subscription plan settings for unauthorized changes.
  • Implement additional security measures to prevent unauthorized access to WordPress options.
  • Perform an asset inventory to identify potentially affected systems.
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Review official advisories for additional guidance on mitigating this vulnerability.

Evidence notes

The CVE record was published on 2026-04-08T05:16:06.130Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify affected product deployments, review official advisories, and monitor for unauthorized changes to subscription plan settings.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-3646 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-3646

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-3646 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3646

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/ltl-freight-quotes-rl-edition/tags/3.3.11/en-hit-to-update-plan.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/ltl-freight-quotes-rl-edition/tags/3.3.11/en-hit-to-update-plan.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/ltl-freight-quotes-rl-edition/tags/3.3.11/en-hit-to-update-plan.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/ltl-freight-quotes-rl-edition/tags/3.3.11/en-hit-to-update-plan.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/ltl-freight-quotes-rl-edition/tags/3.3.11/en-hit-to-update-plan.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/ltl-freight-quotes-rl-edition/tags/3.3.11/en-hit-to-update-plan.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/ltl-freight-quotes-rl-edition/trunk/en-hit-to-update-plan.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.