CVE-2026-3646Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin's webhook handler in all versions up to, and including, 3.3.13. This is due to missing authentication, authorization, and nonce verification on a standalone PHP file that directly processes GET parameters and updates WordPress options. This makes it possible for unauthenticated attackers to modify the plugin's subscription plan settings, effectively downgrading the store from a paid plan to the Trial Plan, changing the store type, and manipulating subscription expiration dates, potentially disabling premium features such as Dropship and Hazardous Material handling.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-08); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-08: 1Mentions · 2026-04-13: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-13: 104-0804-13
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3646 The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin's webhook handler in all versions up to, and in… https://www.cve.org/CVERecord?id=CVE-2026-3646

    Post summary

    The post announces CVE‑2026‑3646 as a missing‑authorization vulnerability in the LTL Freight Quotes plugin, but provides no PoC, exploit, patch, or active exploitation details.

    00000153
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3646 Missing Authorization in LTL Freight Quotes R+L Carriers WordPress Plugin 3.3.13 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3646

    Post summary

    The post discloses CVE-2026-3646 as a missing authorization flaw in the LTL Freight Quotes R+L Carriers WordPress Plugin 3.3.13, providing only basic technical detail and no evidence of a PoC, exploit code, or active exploitation.

    0000057
    4.0K followersView on X

Explore more