PatchSiren cyber security CVE debrief
CVE-2026-3646 enituretechnology CVE debrief
The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin's webhook handler in all versions up to, and including, 3.3.13. This is due to missing authentication, authorization, and nonce verification on a standalone PHP file that directly processes GET parameters and updates WordPress options. This vulnerability allows unauthenticated attackers to modify the plugin's subscription plan settings, effectively downgrading the store from a paid plan to the Trial Plan, changing the store type, and manipulating subscription expiration dates, potentially disabling premium features such as Dropship and Hazardous Material handling. Users should review their current subscription plans and monitor for unauthorized changes.
- Vendor
- enituretechnology
- Product
- LTL Freight Quotes – R+L Carriers Edition
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of the LTL Freight Quotes – R+L Carriers Edition plugin for WordPress should be aware of this vulnerability, as it allows unauthenticated attackers to modify the plugin's subscription plan settings. Affected operators, platform administrators, vulnerability management teams, and security teams should review their current subscription plans and monitor for unauthorized changes.
Technical summary
The vulnerability exists due to missing authentication, authorization, and nonce verification on a standalone PHP file that directly processes GET parameters and updates WordPress options. This makes it possible for unauthenticated attackers to modify the plugin's subscription plan settings, effectively downgrading the store from a paid plan to the Trial Plan, changing the store type, and manipulating subscription expiration dates. The CVSS score of 5.3 indicates a medium severity vulnerability.
Defensive priority
Medium priority given the CVSS score of 5.3 and the potential impact on subscription plan settings. Implement additional security measures to prevent unauthorized access to WordPress options and monitor subscription plan settings for unauthorized changes. Consider compensating controls for exposed systems while remediation is scheduled and verified. Review relevant monitoring, detection, and logs for exposed assets that need extra review. Track exceptions, retest remediated assets, and close the item only after evidence is documented. Update the LTL Freight Quotes – R+L Carriers Edition plugin to a version that includes a fix for this vulnerability. Perform an asset inventory to identify potentially affected systems. Implement rollback/change windows for updates. Track source references for additional information.
Recommended defensive actions
- Update the LTL Freight Quotes – R+L Carriers Edition plugin to a version that includes a fix for this vulnerability.
- Monitor subscription plan settings for unauthorized changes.
- Implement additional security measures to prevent unauthorized access to WordPress options.
- Perform an asset inventory to identify potentially affected systems.
- Review relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Review official advisories for additional guidance on mitigating this vulnerability.
Evidence notes
The CVE record was published on 2026-04-08T05:16:06.130Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify affected product deployments, review official advisories, and monitor for unauthorized changes to subscription plan settings.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T05:16:06.130Z and has not been modified since then. The NVD entry is currently Deferred.