PatchSiren cyber security CVE debrief
CVE-2026-87781 LTL Freight Quotes CVE debrief
The LTL Freight Quotes WordPress plugin versions 4.2.11 to 4.2.18 contain a SQL injection vulnerability exploitable by unauthenticated users. This vulnerability arises from unsanitized and unescaped parameters in a SQL statement. Defenders responsible for WordPress installations with these plugin versions should assess exposure and apply patches. The vulnerability could lead to potential unauthorized database access and data tampering. It is crucial for defenders to verify exposure, apply patches, and monitor for suspicious activity to prevent potential security breaches.
- Vendor
- LTL Freight Quotes
- Product
- LTL Freight Quotes
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations with LTL Freight Quotes plugin versions 4.2.11 to 4.2.18 should assess exposure and apply patches.
Why it matters
The SQL injection vulnerability in LTL Freight Quotes versions 4.2.11 to 4.2.18 requires defenders to verify exposure, apply patches, and monitor for suspicious activity to prevent potential unauthorized database access and data tampering.
- Potential unauthorized database access
- Possible data tampering or extraction
- Required verification of LTL Freight Quotes versions and patch application
- Potential disruption of WordPress functionality
Technical summary
The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. This vulnerability affects plugin versions 4.2.11 to 4.2.18 and could allow attackers to access or tamper with database information. Defenders should prioritize verifying exposure and applying patches for these versions.
Defensive priority
Defenders should prioritize verifying exposure and applying patches for LTL Freight Quotes versions 4.2.11 to 4.2.18.
Recommended defensive actions
- Verify LTL Freight Quotes version and apply patch to versions 4.2.11 to 4.2.18
- Restrict access to the Shipping Rule 'edit_id' parameter
- Monitor for suspicious SQL queries
Evidence notes
The CVE record and source item provide details on the SQL injection vulnerability in LTL Freight Quotes versions 4.2.11 to 4.2.18. The vulnerability is caused by unsanitized and unescaped parameters in a SQL statement, making it exploitable by unauthenticated users. Defenders should verify exposure by checking the plugin version and apply patches to versions 4.2.11 to 4.2.18. The source item and CVE record have limited details, so defenders should exercise caution and consider the CVE
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87781 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87781
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87781 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87781
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
LTL Freight Quotes – Old Dominion Edition 4.2.11 - 4.2.18 - Unauthenticated SQLi via Shipping Ru
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/87xxx/CVE-2026-87781.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/e600ef26-5aec-4e4a-96be-d67875c337a0/
Supplemental source - exploit, vdb-entry, technical-description
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.