CVE-2026-87781: LTL Freight Quotes – Old Dominion Edition 4.2.11 - 4.2.18 - Unauthenticated SQLi via Shipping Rule 'edit_id' Parameter
Published Oct 10, 2026
·Updated
The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
Affected Software
1 affected component
LTL Freight Quotes – Old Dominion Edition<4.2.19
Event History
Oct 10, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated user can exploit it; no WordPress account or plugin-level authentication is required.
2
Which installations are affected?
Installations running LTL Freight Quotes – Old Dominion Edition before version 4.2.19 are affected. The reported affected versions include 4.2.11 through 4.2.18.
3
What input is involved in the vulnerability?
The issue is associated with the Shipping Rule edit_id parameter, which is used in a SQL statement without sufficient sanitization and escaping.