CVE-2026-34899
Description
Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.2.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A missing authorization vulnerability in the LTL Freight Quotes – Worldwide Express Edition plugin for WordPress allows unauthenticated access control bypass.
Vulnerability
Overview
The LTL Freight Quotes – Worldwide Express Edition plugin for WordPress versions up to and including 5.2.1 contains a missing authorization vulnerability [1]. This issue stems from an incorrectly configured access control security level, which fails to properly verify permissions before executing certain functions [1].
Exploitation
This vulnerability can be exploited by an attacker without needing any prior authentication or privileges [1]. The broken access control allows unprivileged users to execute actions that should only be available to higher-privileged users [1]. While considered low severity, such vulnerabilities are reportedly used in mass-exploit campaigns targeting thousands of websites [1].
Impact
Successful exploitation could enable an attacker to perform unauthorized actions within the plugin's functionality, potentially leading to data exposure or configuration changes [1]. The exact impact depends on which specific actions become accessible.
Mitigation
The vulnerability has been patched in version 5.2.2 [1]. Users are strongly advised to update immediately [1]. For those unable to update, contacting a hosting provider or web developer is recommended [1]. Patchstack users can enable auto-updates for vulnerable plugins [1].
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=5.2.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- Wordfence Intelligence Weekly WordPress Vulnerability Report (April 6, 2026 to April 12, 2026)Wordfence Blog · Apr 16, 2026