VYPR
Medium severity5.3NVD Advisory· Published Apr 7, 2026· Updated Apr 24, 2026

CVE-2026-34899

CVE-2026-34899

Description

Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.2.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A missing authorization vulnerability in the LTL Freight Quotes – Worldwide Express Edition plugin for WordPress allows unauthenticated access control bypass.

Vulnerability

Overview

The LTL Freight Quotes – Worldwide Express Edition plugin for WordPress versions up to and including 5.2.1 contains a missing authorization vulnerability [1]. This issue stems from an incorrectly configured access control security level, which fails to properly verify permissions before executing certain functions [1].

Exploitation

This vulnerability can be exploited by an attacker without needing any prior authentication or privileges [1]. The broken access control allows unprivileged users to execute actions that should only be available to higher-privileged users [1]. While considered low severity, such vulnerabilities are reportedly used in mass-exploit campaigns targeting thousands of websites [1].

Impact

Successful exploitation could enable an attacker to perform unauthorized actions within the plugin's functionality, potentially leading to data exposure or configuration changes [1]. The exact impact depends on which specific actions become accessible.

Mitigation

The vulnerability has been patched in version 5.2.2 [1]. Users are strongly advised to update immediately [1]. For those unable to update, contacting a hosting provider or web developer is recommended [1]. Patchstack users can enable auto-updates for vulnerable plugins [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

1