Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin, with AI-generated Chinese analysis, references, and POCs.

ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin is a WordPress plugin distributed by the vendor ShopLentor that addresses weaknesses primarily categorized under cross-site scripting and broken access control. This aggregation page collects reported security vulnerabilities and advisory notices associated with this specific software solution, covering incidents discovered and published between January 2021 and May 2024. The dataset includes confirmed security flaws that affect various versions of the plugin, reflecting both past patches and ongoing risks within the broader ecosystem of WooCommerce extensions. Readers can use this resource to track a vendor's advisories by reviewing the chronological timeline of security updates and public disclosures. You may also understand a weakness class by examining the technical details and attack vectors associated with specific flaw types, such as how input validation failures lead to script injection. Additionally, the page allows you to look up a product's vulnerability history, providing a clear view of how the developer has responded to security challenges over time. This information helps administrators assess the stability of their store environment and determine if their current installation version is susceptible to known exploits. By consolidating these data points, the page offers a centralized reference for security researchers and site owners to evaluate the risk posture of the ShopLentor plugin without relying on scattered news sources or fragmented reports.

Vendor: devitemsllc

CVE ID Title CVSS Severity Published
CVE-2026-6020 ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API CWE-470 7.2 High 2026-08-05
CVE-2026-16811 ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter CWE-89 4.9 Medium 2026-07-28
CVE-2026-16797 ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter CWE-639 4.3 Medium 2026-07-28
CVE-2026-6287 ShopLentor - WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute CWE-79 5.4 Medium 2026-05-27
CVE-2026-4059 ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute CWE-79 6.4 Medium 2026-04-14
CVE-2026-1714 ShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action CWE-93 8.6 High 2026-02-18
CVE-2025-12493 ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template' CWE-22 9.8 Critical 2025-11-04
CVE-2025-11823 ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-80 6.4 Medium 2025-10-25
CVE-2025-3775 ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter CWE-918 6.5 Medium 2025-04-25
CVE-2025-1527 ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module CWE-79 6.4 Medium 2025-03-12
CVE-2024-9538 ShopLentor <= 2.9.8 - Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template CWE-200 4.3 Medium 2024-10-11
CVE-2024-8668 ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-09-25
CVE-2024-5530 ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Product Horizontal Filter Widget CWE-79 6.4 Medium 2024-06-11
CVE-2024-3345 ShopLentor <= 2.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via woolentorsearch Shortcode CWE-79 6.4 Medium 2024-05-21
CVE-2024-4566 ShopLentor <= 2.8.8 - Missing Authorization to WordPress Option Modification CWE-862 7.1 High 2024-05-21
CVE-2023-6327 ShopLentor (formerly WooLentor) <= 2.8.7 - Missing Authorization via purchased_new_products CWE-862 5.3 Medium 2024-05-09
CVE-2023-7067 ShopLentor <= 2.8.1 - Improper Authorization via woolentor_template_store CWE-862 4.3 Medium 2024-05-02
CVE-2024-3991 ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.7 - Authenticated (contributor+) Stored Cross-Site Scripting via _id CWE-79 6.4 Medium 2024-05-02
CVE-2024-1057 ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-04-20
CVE-2024-2946 ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.4 - Authenticated (Contributor+) Stored Cross-site Scripting via QR Code Widget CWE-79 6.4 Medium 2024-04-09
CVE-2024-1960 ShopLentor <= 2.8.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Banner Link CWE-79 6.4 Medium 2024-04-09
CVE-2024-2868 ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Universal Product Layout CWE-79 6.4 Medium 2024-04-04

All 22 known CVE vulnerabilities affecting ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin with full Chinese analysis, references, and POCs where available.