The LTL Freight Quotes WordPress plugin versions 4.2.11 to 4.2.18 contain a SQL injection vulnerability exploitable by unauthenticated users. This vulnerability arises from unsanitized and unescaped parameters in a SQL statement. Defenders responsible for WordPress installations with these plugin versions should assess exposure and apply patches. The vulnerability could lead to potential unauthorized data [truncated]
The LTL Freight Quotes WordPress plugin before 4.2.19 does not properly sanitize and escape values submitted through an unauthenticated endpoint, leading to Stored XSS. This vulnerability allows attackers to execute malicious scripts in the session of any administrator viewing the affected page. Defenders should assess exposure and prioritize updating to version 4.2.19 or later. The plugin's lack of input [truncated]