← WordPress Vulnerabilities
WordPress security by component

Small Package Quotes – Unishippers Edition

Small Package Quotes – Unishippers Edition is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Mar 03, 2025; the highest CVE/CNA score is 7.5.

Plugin slug: small-package-quotes

CVE-2025-26918: Small Package Quotes – Unishippers Edition: Cross-site scripting

Small Package Quotes – Unishippers Edition is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedMar 03, 2025
Safe version guidanceSee mitigation notes
Safe version
Mar 03, 2025 CVE-2025-26918
Small Package Quotes – Unishippers Edition: Cross-site scripting
Small Package Quotes – Unishippers Edition is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Feb 19, 2025 CVE-2024-13534
Small Package Quotes – Worldwide Express Edition: SQL injection
Small Package Quotes – Worldwide Express Edition is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVD7.5
Feb 19, 2025 CVE-2024-13491
Small Package Quotes – For Customers of FedEx: SQL injection
Small Package Quotes – For Customers of FedEx is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending
Feb 12, 2025 CVE-2024-13532
Small Package Quotes – Purolator Edition: SQL injection
Small Package Quotes – Purolator Edition is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVD7.5
Feb 12, 2025 CVE-2024-13475
Small Package Quotes – UPS Edition: SQL injection
Small Package Quotes – UPS Edition is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVD7.5