PatchSiren cyber security CVE debrief
CVE-2026-3646 enituretechnology CVE debrief
The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin's webhook handler in all versions up to, and including, 3.3.13. This is due to missing authentication, authorization, and nonce verification on a standalone PHP file that directly processes GET parameters and updates WordPress options. This vulnerability allows unauthenticated attackers to modify the plugin's subscription plan settings, effectively downgrading the store from a paid plan to the Trial Plan, changing the store type, and manipulating subscription expiration dates, potentially disabling premium features such as Dropship and Hazardous Material handling. Users should review their current subscription plans and monitor for unauthorized changes.
- Vendor
- enituretechnology
- Product
- LTL Freight Quotes – R+L Carriers Edition
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of the LTL Freight Quotes – R+L Carriers Edition plugin for WordPress should be aware of this vulnerability, as it allows unauthenticated attackers to modify the plugin's subscription plan settings. Affected operators, platform administrators, vulnerability management teams, and security teams should review their current subscription plans and monitor for unauthorized changes.
Technical summary
The vulnerability exists due to missing authentication, authorization, and nonce verification on a standalone PHP file that directly processes GET parameters and updates WordPress options. This makes it possible for unauthenticated attackers to modify the plugin's subscription plan settings, effectively downgrading the store from a paid plan to the Trial Plan, changing the store type, and manipulating subscription expiration dates. The CVSS score of 5.3 indicates a medium severity vulnerability.
Defensive priority
Medium priority given the CVSS score of 5.3 and the potential impact on subscription plan settings. Implement additional security measures to prevent unauthorized access to WordPress options and monitor subscription plan settings for unauthorized changes. Consider compensating controls for exposed systems while remediation is scheduled and verified. Review relevant monitoring, detection, and logs for exposed assets that need extra review. Track exceptions, retest remediated assets, and close the item only after evidence is documented. Update the LTL Freight Quotes – R+L Carriers Edition plugin to a version that includes a fix for this vulnerability. Perform an asset inventory to identify potentially affected systems. Implement rollback/change windows for updates. Track source references for additional information.
Recommended defensive actions
- Update the LTL Freight Quotes – R+L Carriers Edition plugin to a version that includes a fix for this vulnerability.
- Monitor subscription plan settings for unauthorized changes.
- Implement additional security measures to prevent unauthorized access to WordPress options.
- Perform an asset inventory to identify potentially affected systems.
- Review relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Review official advisories for additional guidance on mitigating this vulnerability.
Evidence notes
The CVE record was published on 2026-04-08T05:16:06.130Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify affected product deployments, review official advisories, and monitor for unauthorized changes to subscription plan settings.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-3646 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-3646
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-3646 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3646
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/ltl-freight-quotes-rl-edition/tags/3.3.11/en-hit-to-update-plan.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/ltl-freight-quotes-rl-edition/tags/3.3.11/en-hit-to-update-plan.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/ltl-freight-quotes-rl-edition/tags/3.3.11/en-hit-to-update-plan.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/ltl-freight-quotes-rl-edition/tags/3.3.11/en-hit-to-update-plan.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/ltl-freight-quotes-rl-edition/tags/3.3.11/en-hit-to-update-plan.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/ltl-freight-quotes-rl-edition/tags/3.3.11/en-hit-to-update-plan.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/ltl-freight-quotes-rl-edition/trunk/en-hit-to-update-plan.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.