CVE-2025-58643
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-03

Last updated on: 2026-04-23

Assigner: Patchstack

Description
Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Daylight Edition ltl-freight-quotes-daylight-edition allows Object Injection.This issue affects LTL Freight Quotes – Daylight Edition: from n/a through <= 2.2.7.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-03
Last Modified
2026-04-23
Generated
2026-05-27
AI Q&A
2025-09-03
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
enituretechnology ltl_freight_quotes_daylight_edition *
wordpress ltl_freight_quotes_daylight_edition_plugin 2.2.7
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2025-58643 is a PHP Object Injection vulnerability in the WordPress LTL Freight Quotes – Daylight Edition plugin (versions up to 2.2.7). It allows an attacker with administrator-level privileges to exploit a suitable PHP Object Injection Property Oriented Programming (POP) chain to potentially execute arbitrary code, perform SQL injection, path traversal, denial of service, and other attacks. The vulnerability arises from deserialization of untrusted data. [1]


How can this vulnerability impact me? :

If exploited, this vulnerability can lead to severe impacts including arbitrary code execution, SQL injection, path traversal, and denial of service on the affected system. However, exploitation requires administrator-level access, which limits the attack surface. The overall severity is considered low, but successful exploitation could compromise confidentiality, integrity, and availability of the system. [1]


How can this vulnerability be detected on my network or system? Can you suggest some commands?

Detection of this vulnerability involves identifying if the WordPress LTL Freight Quotes – Daylight Edition plugin version is 2.2.7 or earlier installed on your system. Since it requires administrator privileges to exploit, monitoring for unusual administrator activity or unexpected PHP object injection attempts may help. However, no specific detection commands are provided. It is also recommended to avoid relying solely on plugin-based malware scanners as they can be tampered with by malware. [1]


What immediate steps should I take to mitigate this vulnerability?

The immediate mitigation step is to update the LTL Freight Quotes – Daylight Edition plugin to version 2.2.8 or later, where the vulnerability is fixed. Alternatively, Patchstack offers a virtual patching (vPatch) solution that can auto-mitigate the vulnerability before official patches are applied. Additionally, general security best practices include using professional incident response services if compromise is suspected and avoiding reliance on plugin-based malware scanners. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart