CVE-2026-87780
Received Received - Intake

Stored Cross-Site Scripting in LTL Freight Quotes WordPress Plugin

Vulnerability report for CVE-2026-87780, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: WPScan

Description

The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape values submitted through an unauthenticated endpoint before storing them and outputting them back in an administrative page, leading to Stored XSS which will execute in the session of any administrator viewing it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown LTL Freight Quotes 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The LTL Freight Quotes WordPress plugin before version 4.2.19 has a stored cross-site scripting (XSS) vulnerability. It fails to sanitize and escape user input submitted through an unauthenticated endpoint. This allows attackers to inject malicious scripts that are stored in the database and executed when an administrator views the affected page.

Detection Guidance

Check if the LTL Freight Quotes WordPress plugin version is below 4.2.19. Inspect the Shipping Rules feature for unsanitized input in the administrative interface. Look for stored XSS payloads in database entries related to the plugin.

Impact Analysis

An attacker could exploit this to execute malicious scripts in the browser of an administrator viewing the affected page. This could lead to session hijacking, unauthorized actions on the site, or theft of sensitive data like admin credentials.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate GDPR (data protection) or HIPAA (health data privacy) requirements. Non-compliance could result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Update the LTL Freight Quotes plugin to version 4.2.19 or later immediately. If updating is not possible, disable the plugin until a patch is applied. Monitor administrative pages for suspicious scripts or unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87780. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart