Small Package Quotes – Unishippers Edition
Small Package Quotes – Unishippers Edition has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 3 are fixed as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 1 of the records (33%). Other recurring categories include Missing Authorization, SQL Injection.
Every one of the 3 issues recorded for Small Package Quotes – Unishippers Edition has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. Small Package Quotes – Unishippers Edition is installed on roughly 60 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-24665Small Package Quotes – Unishippers Edition <= 2.4.8 - Unauthenticated SQL Injection
Read the full analysisVulnerability Records

Small Package Quotes – Unishippers Edition
Author
enituretechnology
woocommerceA more connected world means more opportunities. That’s why customers count on our diverse portfolio of transportation, e-commerce, and business solutions. Our air, ground and sea networks cover more than 220 countries and territories, linking more than 99 percent of the world’s GDP. Key Features Includes negotiated shipping rates in the shopping cart and on the checkout page. Ability to control which Unishippers services to display Support for variable products. Define multiple warehouses and drop ship locations Option to include residential delivery surcharge Option to mark up shipping rates by a set dollar amount or by a percentage. Requirements WooCommerce 6.4 or newer. A Unishippers customer number. A Unishippers issued UPS account number. Your username and password to Unishippers. A Unishippers issued Request Key. An API key from Eniture Technology.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C