ShipEngine Shipping Quotes
ShipEngine Shipping Quotes has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 7.5, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is SQL Injection, behind 1 of the records (100%).
The one issue recorded for ShipEngine Shipping Quotes has a vendor fix available, so running the current release closes it.
All of these findings were reported by Colin Xu. The current release is tested up to WordPress 7.1.
CVE-2024-13531ShipEngine Shipping Quotes <= 1.0.7 - Unauthenticated SQL Injection
Read the full analysisVulnerability Records

ShipEngine Shipping Quotes
Author
enituretechnology
Dynamically retrieves your discounted shipping rates and displays the results in the WooCommerce shopping cart. Key Features Includes negotiated shipping rates in the shopping cart and on the checkout page. Ability to control which UPS small package services to display Support for variable products. Option to mark up shipping rates by a set dollar amount or by a percentage. Requirements WooCommerce 6.4 or newer. A license from Eniture Technology. External Service Usage This plugin relies on a 3rd party service provided by Eniture Technology to fetch live shipping rates and perform other related functionalities. Please review the following information regarding the usage of this service: Functionality: This plugin displays live shipping rates of multiple shipping carriers such as UPS, FedEx, DHL, etc., on the cart and checkout pages of your WooCommerce store. To achieve this functionality, the plugin sends cart data and API credentials provided by the user on the connection settings page to Eniture’s Webservices. Data Transmission: During the live shipping rate calculation process, the plugin sends essential cart information, such as product details, quantities, and shipping destination, to Eniture Webservices. This data is used to accurately quote shipping rates from various carriers. The data transmission occurs during the execution of a specific function within the plugin’s code. Specifically, the request is sent on line 41 of the shipengine-eniture/http/en-curl.php file. Additionally, the same function mentioned above is used to test the API credentials and retrieve the lowest distance between multiple warehouses. Service Provider: The external service is provided by Eniture Technology. https://www.eniture.com/ It’s important to note that the usage of external services is properly documented here to ensure transparency and legal compliance. Users are encouraged to review the terms of use and privacy policy of the service provider for further information.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C