CVE-2024-13473

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 12, 2025
Updated: Feb 18, 2025
CWE ID 89

Summary

CVE-2024-13473 is a vulnerability affecting the LTL Freight Quotes – Worldwide Express Edition plugin for WordPress. This issue allows unauthenticated attackers to execute SQL Injections through the 'dropship_edit_id' and 'edit_id' parameters due to insufficient escaping and unprepared SQL queries. As a result, attackers can append additional SQL queries to existing ones, extracting sensitive information from the database. This vulnerability can pose a significant risk to websites using this plugin, making it essential to apply the necessary patches or updates as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Ltl Freight Quotes Plugin

Affected Vendors

  • WordPress