CVE-2025-24664
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-24664 is a SQL Injection vulnerability discovered in Eniture Technology's LTL Freight Quotes – Worldwide Express Edition plugin. The vulnerability was identified on January 18, 2025, by researcher Colin Xu and affects all versions through 5.0.20. This critical vulnerability stems from improper neutralization of special elements used in SQL commands, allowing unauthenticated attackers to perform SQL injection attacks (Patchstack, WPScan).

Technical details

The vulnerability has received a CVSS v3.1 score of 9.3 (Critical) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L. The issue arises from insufficient escaping of user-supplied parameters and lack of proper preparation in existing SQL queries. This allows attackers to append additional SQL queries to extract sensitive information from the database. The vulnerability is classified under CWE-89: Improper Neutralization of Special Elements used in SQL Commands (NVD, TheSecMaster).

Impact

The vulnerability's impact is severe, allowing attackers to potentially access sensitive customer data, including personally identifiable information (PII), financial records, and proprietary business data. Successful exploitation could lead to unauthorized database access, data modification, service disruption, or complete database compromise. The altered scope indicated by the CVSS vector (S:C) suggests that the vulnerable component can affect resources beyond its security scope (TheSecMaster).

Mitigation and workarounds

The primary mitigation strategy is to update to version 5.0.21 or later, which contains the fix for this vulnerability. Additional recommended security measures include implementing robust input validation, using parameterized queries, applying the principle of least privilege for database accounts, deploying a Web Application Firewall (WAF), and conducting regular security audits (TheSecMaster, Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-47552CRITICAL9.8
  • dzs-videogallery
NoNoJan 07, 2026
CVE-2025-46494HIGH7.1
  • widgetkit-pro
NoNoJan 07, 2026
CVE-2025-46434MEDIUM6.5
  • theplus_elementor_addon
NoYesJan 07, 2026
CVE-2025-14275MEDIUM6.4
  • jeg-elementor-kit
NoYesJan 08, 2026
CVE-2025-12640MEDIUM4.3
  • folders
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management