First published: Sun Feb 16 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology LTL Freight Quotes – FreightQuote Edition allows SQL Injection. This issue affects LTL Freight Quotes – FreightQuote Edition: from n/a through 2.3.11.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress LTL Freight Quotes – FreightQuote Edition Plugin | >=2.3.11 | |
WordPress LTL Freight Quotes – FreightQuote Edition Plugin | <=2.3.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22290 is classified as a high severity vulnerability due to its potential for SQL Injection attacks.
To fix CVE-2025-22290, update the LTL Freight Quotes – FreightQuote Edition plugin to version 2.3.12 or later.
CVE-2025-22290 affects the LTL Freight Quotes – FreightQuote Edition plugin versions up to and including 2.3.11.
CVE-2025-22290 is an SQL Injection vulnerability that allows attackers to manipulate database queries.
No specific workaround is recommended for CVE-2025-22290, and upgrading is the best option to mitigate the risk.