Small Package Quotes – USPS Edition <= 1.3.9 - Authenticated (Administrator+) PHP Object Injection
medium
The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.9 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is...
- CVSS:
- 6.6
- Affected:
- up to 1.3.9
- Fixed in:
- 1.3.10
- Disclosed:
- Aug 27, 2025
CVE-2025-58218 on NVD →
Small Package Quotes – USPS Edition [small-package-quotes-usps-edition] < 1.3.10
unknown
[en] Deserialization of Untrusted Data vulnerability in enituretechnology Small Package Quotes – USPS Edition allows Object Injection. This issue affects Small Package Quotes – USPS Edition: from n/a through 1.3.9.
- Affected:
- up to 1.3.10
- Fixed in:
- 1.3.10
- Disclosed:
- Aug 27, 2025
CVE-2025-58218 on NVD →
Small Package Quotes – USPS Edition [small-package-quotes-usps-edition] < 1.3.6 (closed)
unknown
[en] The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 1.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for u...
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- Feb 19, 2025
CVE-2024-13533 on NVD →
Small Package Quotes – USPS Edition <= 1.3.5 - Unauthenticated SQL Injection
high
The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 1.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauth...
- CVSS:
- 7.5
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.6
- Disclosed:
- Feb 18, 2025
CVE-2024-13533 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database