PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3646 enituretechnology CVE debrief

The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin's webhook handler in all versions up to, and including, 3.3.13. This is due to missing authentication, authorization, and nonce verification on a standalone PHP file that directly processes GET parameters and updates WordPress options. This vulnerability allows unauthenticated attackers to modify the plugin's subscription plan settings, effectively downgrading the store from a paid plan to the Trial Plan, changing the store type, and manipulating subscription expiration dates, potentially disabling premium features such as Dropship and Hazardous Material handling. Users should review their current subscription plans and monitor for unauthorized changes.

Vendor
enituretechnology
Product
LTL Freight Quotes – R+L Carriers Edition
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of the LTL Freight Quotes – R+L Carriers Edition plugin for WordPress should be aware of this vulnerability, as it allows unauthenticated attackers to modify the plugin's subscription plan settings. Affected operators, platform administrators, vulnerability management teams, and security teams should review their current subscription plans and monitor for unauthorized changes.

Technical summary

The vulnerability exists due to missing authentication, authorization, and nonce verification on a standalone PHP file that directly processes GET parameters and updates WordPress options. This makes it possible for unauthenticated attackers to modify the plugin's subscription plan settings, effectively downgrading the store from a paid plan to the Trial Plan, changing the store type, and manipulating subscription expiration dates. The CVSS score of 5.3 indicates a medium severity vulnerability.

Defensive priority

Medium priority given the CVSS score of 5.3 and the potential impact on subscription plan settings. Implement additional security measures to prevent unauthorized access to WordPress options and monitor subscription plan settings for unauthorized changes. Consider compensating controls for exposed systems while remediation is scheduled and verified. Review relevant monitoring, detection, and logs for exposed assets that need extra review. Track exceptions, retest remediated assets, and close the item only after evidence is documented. Update the LTL Freight Quotes – R+L Carriers Edition plugin to a version that includes a fix for this vulnerability. Perform an asset inventory to identify potentially affected systems. Implement rollback/change windows for updates. Track source references for additional information.

Recommended defensive actions

  • Update the LTL Freight Quotes – R+L Carriers Edition plugin to a version that includes a fix for this vulnerability.
  • Monitor subscription plan settings for unauthorized changes.
  • Implement additional security measures to prevent unauthorized access to WordPress options.
  • Perform an asset inventory to identify potentially affected systems.
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Review official advisories for additional guidance on mitigating this vulnerability.

Evidence notes

The CVE record was published on 2026-04-08T05:16:06.130Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify affected product deployments, review official advisories, and monitor for unauthorized changes to subscription plan settings.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T05:16:06.130Z and has not been modified since then. The NVD entry is currently Deferred.