VYPR
Critical severity9.3NVD Advisory· Published Jan 27, 2025· Updated Apr 23, 2026

CVE-2025-24664

CVE-2025-24664

Description

SQL Injection vulnerability in WordPress LTL Freight Quotes plugin version ≤5.0.20 allows unauthenticated attackers to extract database information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SQL Injection vulnerability in WordPress LTL Freight Quotes plugin version ≤5.0.20 allows unauthenticated attackers to extract database information.

Vulnerability

Details

The LTL Freight Quotes – Worldwide Express Edition plugin for WordPress, developed by enituretechnology, contains an SQL Injection vulnerability in versions up to and including 5.0.20. The issue arises from improper neutralization of special elements used in an SQL command, allowing attackers to inject arbitrary SQL queries. This vulnerability is classified as Critical with a CVSS score of 9.3, indicating severe risk [1].

Exploitation

Exploitation does not require authentication, making the attack surface broad. An attacker can send crafted HTTP requests to vulnerable endpoints to inject malicious SQL statements. The vulnerability is expected to be exploited in mass campaigns targeting thousands of websites regardless of traffic size or popularity [1].

Impact

Successful exploitation allows an attacker to interact with the WordPress database directly, potentially stealing sensitive information such as user credentials, personal data, or other stored content. The attacker could also modify or delete database entries, leading to further compromise of the site [1].

Mitigation

The vendor has released version 5.0.21 to patch the vulnerability. Users are strongly advised to update immediately. Patchstack also provides a mitigation rule to block attacks until the update is applied. If unable to update, consulting a hosting provider or web developer is recommended [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

1
v5.1.6

Release: ltl-freight-quotes-worldwide-express-edition 5.1.6 (next version after vulnerable 5.0.20)

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.