ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API
high
The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint in all versions up to, and including, 3.3.7. This is due to the handle_action() method passing user-supplied input directly to call_user_func() without an allowlist of permitted call...
- CVSS:
- 7.2
- Affected:
- up to 3.3.7
- Fixed in:
- 3.3.8
- Disclosed:
- Aug 4, 2026
CVE-2026-6020 on NVD →
ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter
medium
The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.5 via the 'optionSection' parameter due to missing validation on a user controlled key. This makes it possible for authenticated atta...
- CVSS:
- 4.3
- Affected:
- up to 3.4.5
- Fixed in:
- 3.4.6
- Disclosed:
- Jul 27, 2026
CVE-2026-16797 on NVD →
ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
medium
The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing...
- CVSS:
- 4.9
- Affected:
- up to 3.4.5
- Fixed in:
- 3.4.6
- Disclosed:
- Jul 27, 2026
CVE-2026-16811 on NVD →
ShopLentor - WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute
medium
The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId' block attribute in multiple Product Gride blocks in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possib...
- CVSS:
- 5.4
- Affected:
- up to 3.3.8
- Fixed in:
- 3.3.9
- Disclosed:
- May 26, 2026
CVE-2026-6287 on NVD →
ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute
medium
The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentor_quickview_button shortcode's button_text attribute in all versions up to, and including, 3.3.5. This is due to insufficient input sanitization and missing output escaping on user-supplied shortcode attributes. This makes...
- CVSS:
- 6.4
- Affected:
- up to 3.3.5
- Fixed in:
- 3.3.6
- Disclosed:
- Apr 13, 2026
CVE-2026-4059 on NVD →
ShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action
high
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abuse in all versions up to, and including, 3.3.2 This is due to the lack of validation on the 'send_to', 'product_title', 'wlmessage', and 'wlemail' parameters in the 'wool...
- CVSS:
- 8.6
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.3
- Disclosed:
- Feb 17, 2026
CVE-2026-1714 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 3.2.6
unknown
[en] The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the 'load_template' function. This makes it possible for unauthenticated attackers to incl...
- Affected:
- up to 3.2.6
- Fixed in:
- 3.2.6
- Disclosed:
- Nov 4, 2025
CVE-2025-12493 on NVD →
ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template'
critical
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the 'load_template' function. This makes it possible for unauthenticated attackers to include a...
- CVSS:
- 9.8
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.6
- Disclosed:
- Nov 3, 2025
CVE-2025-12493 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 3.2.5
unknown
[en] The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_exist_text' parameter in the 'wishsuite_button' shortcode in all versions up to, and including, 3.2.4 due to insufficient input sanitiza...
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- Oct 25, 2025
CVE-2025-11823 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_exist_text' parameter in the 'wishsuite_button' shortcode in all versions up to, and including, 3.2.4 due to insufficient input sanitization...
- CVSS:
- 6.4
- Affected:
- up to 3.2.4
- Fixed in:
- 3.2.5
- Disclosed:
- Oct 24, 2025
CVE-2025-11823 on NVD →
ShopLentor <= 3.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.1
- Disclosed:
- Sep 9, 2025
CVE-2025-58990 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 3.2.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasTech ShopLentor allows Stored XSS. This issue affects ShopLentor: from n/a through 3.2.0.
- Affected:
- up to 3.2.1
- Fixed in:
- 3.2.1
- Disclosed:
- Sep 9, 2025
CVE-2025-58990 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter
medium
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.2 via the woolentor_template_proxy function. This makes it possible for unauthenticated attack...
- CVSS:
- 6.5
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.3
- Disclosed:
- Apr 24, 2025
CVE-2025-3775 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module
medium
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to a Stored DOM-Based Cross-Site Scripting via the plugin's Flash Sale Countdown module in all versions up to, and including, 3.1.0 due to insufficient input sanitizat...
- CVSS:
- 6.4
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.1
- Disclosed:
- Mar 11, 2025
CVE-2025-1527 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.9.9
unknown
[en] The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.8 via the 'render' function in includes/addons/wl_faq.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending...
- Affected:
- up to 2.9.9
- Fixed in:
- 2.9.9
- Disclosed:
- Oct 11, 2024
CVE-2024-9538 on NVD →
ShopLentor <= 2.9.8 - Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template
medium
The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.8 via the 'render' function in includes/addons/wl_faq.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and...
- CVSS:
- 4.3
- Affected:
- up to 2.9.8
- Fixed in:
- 2.9.9
- Disclosed:
- Oct 10, 2024
CVE-2024-9538 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.9.8
unknown
[en] The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tooltip and countdown functionality in all versions up to, and including, 2.9.7 due to insufficient input sanitization and...
- Affected:
- up to 2.9.8
- Fixed in:
- 2.9.8
- Disclosed:
- Sep 25, 2024
CVE-2024-8668 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
medium
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tooltip and countdown functionality in all versions up to, and including, 2.9.7 due to insufficient input sanitization and outpu...
- CVSS:
- 6.4
- Affected:
- up to 2.9.7
- Fixed in:
- 2.9.8
- Disclosed:
- Sep 24, 2024
CVE-2024-8668 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.9.1
unknown
[en] The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's WL: Product Horizontal Filter widget in all versions up to, and including, 2.9.0 due to insufficient input sanitiz...
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1
- Disclosed:
- Jun 11, 2024
CVE-2024-5530 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Product Horizontal Filter Widget
medium
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's WL: Product Horizontal Filter widget in all versions up to, and including, 2.9.0 due to insufficient input sanitization...
- CVSS:
- 6.4
- Affected:
- up to 2.9.0
- Fixed in:
- 2.9.1
- Disclosed:
- Jun 10, 2024
CVE-2024-5530 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.8.8
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes ShopLentor allows Stored XSS.This issue affects ShopLentor: from n/a through 2.8.7.
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- Jun 3, 2024
CVE-2024-34767 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.8.9
unknown
[en] The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortcode in all versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with co...
- Affected:
- up to 2.8.9
- Fixed in:
- 2.8.9
- Disclosed:
- May 21, 2024
CVE-2024-3345 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.8.9
unknown
[en] The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function in all versions up to, and including, 2.8.8. This makes it possible for authenticated attackers, with contributor-level access and above, to set arbitrary WordPress...
- Affected:
- up to 2.8.9
- Fixed in:
- 2.8.9
- Disclosed:
- May 21, 2024
CVE-2024-4566 on NVD →
ShopLentor <= 2.8.8 - Missing Authorization to WordPress Option Modification
high
The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function in all versions up to, and including, 2.8.8. This makes it possible for authenticated attackers, with contributor-level access and above, to set arbitrary WordPress optio...
- CVSS:
- 7.1
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.9
- Disclosed:
- May 20, 2024
CVE-2024-4566 on NVD →
ShopLentor <= 2.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via woolentorsearch Shortcode
medium
The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortcode in all versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contrib...
- CVSS:
- 6.4
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.9
- Disclosed:
- May 20, 2024
CVE-2024-3345 on NVD →
ShopLentor <= 2.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.8
- Disclosed:
- May 17, 2024
CVE-2024-34767 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.8.8
unknown
[en] The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to view all products purchased in the past...
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- May 9, 2024
CVE-2023-6327 on NVD →
ShopLentor (formerly WooLentor) <= 2.8.7 - Missing Authorization via purchased_new_products
medium
The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to view all products purchased in the past week...
- CVSS:
- 5.3
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.8
- Disclosed:
- May 3, 2024
CVE-2023-6327 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.7 - Authenticated (contributor+) Stored Cross-Site Scripting via _id
medium
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute in the Horizontal Product Filter in all versions up to, and including, 2.8.7 due to insufficient input sanitizatio...
- CVSS:
- 6.4
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.8
- Disclosed:
- May 2, 2024
CVE-2024-3991 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.8.2
unknown
[en] The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woolentor_template_store' function in all versions up to, and including, 2.8.1. Thi...
- Affected:
- up to 2.8.2
- Fixed in:
- 2.8.2
- Disclosed:
- May 2, 2024
CVE-2023-7067 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.8.8
unknown
[en] The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute in the Horizontal Product Filter in all versions up to, and including, 2.8.7 due to insufficient input saniti...
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- May 2, 2024
CVE-2024-3991 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.8.2
unknown
[en] The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishsuite_button' shortcode in all versions up to, and including, 2.8.1 due to insufficient input sanitization an...
- Affected:
- up to 2.8.2
- Fixed in:
- 2.8.2
- Disclosed:
- Apr 20, 2024
CVE-2024-1057 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishsuite_button' shortcode in all versions up to, and including, 2.8.1 due to insufficient input sanitization and out...
- CVSS:
- 6.4
- Affected:
- up to 2.8.1
- Fixed in:
- 2.8.2
- Disclosed:
- Apr 19, 2024
CVE-2024-1057 on NVD →
ShopLentor <= 2.8.1 - Improper Authorization via woolentor_template_store
medium
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woolentor_template_store' function in all versions up to, and including, 2.8.1. This mak...
- CVSS:
- 4.3
- Affected:
- up to 2.8.1
- Fixed in:
- 2.8.2
- Disclosed:
- Apr 18, 2024
CVE-2023-7067 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.8.2
unknown
[en] The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Special Offer Day Widget Banner Link in all versions up to, and including, 2.8.1 due to insufficient input sanitization and...
- Affected:
- up to 2.8.2
- Fixed in:
- 2.8.2
- Disclosed:
- Apr 9, 2024
CVE-2024-1960 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.8.5
unknown
[en] The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's QR Code Widget in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escap...
- Affected:
- up to 2.8.5
- Fixed in:
- 2.8.5
- Disclosed:
- Apr 9, 2024
CVE-2024-2946 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.4 - Authenticated (Contributor+) Stored Cross-site Scripting via QR Code Widget
medium
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's QR Code Widget in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping o...
- CVSS:
- 6.4
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.5
- Disclosed:
- Apr 4, 2024
CVE-2024-2946 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.8.4
unknown
[en] The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slitems parameter in the WL Special Day Offer Widget in all versions up to, and including, 2.8.3 due to insufficient input...
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.4
- Disclosed:
- Apr 4, 2024
CVE-2024-2868 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Universal Product Layout
medium
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slitems parameter in the WL Special Day Offer Widget in all versions up to, and including, 2.8.3 due to insufficient input sanit...
- CVSS:
- 6.4
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.4
- Disclosed:
- Apr 3, 2024
CVE-2024-2868 on NVD →
ShopLentor <= 2.8.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Banner Link
medium
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Special Offer Day Widget Banner Link in all versions up to, and including, 2.8.1 due to insufficient input sanitization and outp...
- CVSS:
- 6.4
- Affected:
- up to 2.8.1
- Fixed in:
- 2.8.2
- Disclosed:
- Mar 14, 2024
CVE-2024-1960 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.6.3
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.6.2 versions.
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.3
- Disclosed:
- Jul 17, 2023
CVE-2022-47172 on NVD →
WooLentor <= 2.6.2 - Cross-Site Request Forgery via process_data
medium
The WooLentor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation on the process_data function. This makes it possible for unauthenticated attackers to change plugin settings via a forged request granted they can...
- CVSS:
- 4.3
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.3
- Disclosed:
- Jul 5, 2023
CVE-2022-47172 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.5.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change.
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.2
- Disclosed:
- Mar 1, 2023
CVE-2022-46798 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.5.4
unknown
[en] The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.4
- Disclosed:
- Feb 21, 2023
CVE-2023-0232 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 2.5.4
unknown
[en] The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.4
- Disclosed:
- Feb 21, 2023
CVE-2023-0231 on NVD →
ShopLentor <= 2.5.1 - Cross-Site Request Forgery to Post Updates
medium
The ShopLentor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on the 'templates_ajax_request' function. This makes it possible for unauthenticated attackers to update post metadata such as titles and id numbe...
- CVSS:
- 5.4
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.2
- Disclosed:
- Feb 6, 2023
CVE-2022-46798 on NVD →
WooLentor <= 2.5.3 - PHP Object Injection
critical
The WooLentor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.3 via deserialization of untrusted input in the function woolentor_set_views_count, which unserializes a user-provided cookie. This allows unauthenticated attackers to inject a PHP Object. No POP chain is pres...
- CVSS:
- 9.8
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.4
- Disclosed:
- Jan 28, 2023
CVE-2023-0232 on NVD →
WooLentor <= 2.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The WooLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 2.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and abov...
- CVSS:
- 6.4
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.4
- Disclosed:
- Jan 28, 2023
CVE-2023-0231 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 1.8.6
unknown
[en] The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
- Disclosed:
- May 5, 2021
CVE-2021-24262 on NVD →
WooLentor – WooCommerce Elementor Addons + Builder <= 1.8.5 - Authenticated Stored Cross-Site Scripting
medium
The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
- CVSS:
- 6.4
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
- Disclosed:
- Apr 13, 2021
CVE-2021-24262 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 1.8.6
unknown
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress WooLentor plugin (versions <= 1.8.5).
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
- Disclosed:
- Apr 13, 2021
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 3.1.1
unknown
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
CVE-2025-1527 on NVD →
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) [woolentor-addons] < 3.1.3
unknown
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
CVE-2025-3775 on NVD →