PT-2026-31077 · WordPress · Ltl Freight Quotes – R+L Carriers Edition

Phong Nguyen

·

Published

2026-04-08

·

Updated

2026-04-13

·

CVE-2026-3646

CVSS v3.1

5.3

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions LTL Freight Quotes – R+L Carriers Edition plugin for WordPress versions up to and including 3.3.13
Description The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is susceptible to unauthorized access due to missing authentication, authorization, and nonce verification in its webhook handler. A standalone PHP file directly processes GET parameters and updates WordPress options without proper security checks. This allows unauthenticated attackers to modify the plugin’s subscription plan settings, potentially downgrading a paid plan to the Trial Plan, altering the store type, and manipulating subscription expiration dates, which could disable premium features like Dropship and Hazardous Material handling.
Recommendations Update the LTL Freight Quotes – R+L Carriers Edition plugin to a version beyond 3.3.13.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-3646

Affected Products

Ltl Freight Quotes – R+L Carriers Edition