First published: Mon Jan 27 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eniture Technology LTL Freight Quotes – Worldwide Express Edition allows SQL Injection. This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.0.20.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress LTL Freight Quotes Plugin | >=5.0.20 | |
WordPress LTL Freight Quotes Plugin | <=5.0.20 |
Update the WordPress LTL Freight Quotes – Worldwide Express Edition wordpress plugin to the latest available version (at least 5.0.21).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24664 has a high severity due to its potential for SQL Injection, which can lead to unauthorized access to sensitive data.
To fix CVE-2025-24664, update the Eniture Technology LTL Freight Quotes – Worldwide Express Edition to the latest version beyond 5.0.20.
CVE-2025-24664 affects Eniture Technology LTL Freight Quotes – Worldwide Express Edition versions from n/a through 5.0.20.
Users of affected versions of Eniture Technology LTL Freight Quotes may be vulnerable to SQL Injection attacks, compromising their database security.
To prevent SQL Injection vulnerabilities like CVE-2025-24664, ensure that all input data is properly sanitized and use prepared statements in database queries.