ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin adds WooCommerce shop, product, cart, checkout, and other store-building elements for Elementor and Gutenberg.
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin (woolentor-addons) is a WordPress plugin with 18 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 9.8.
woolentor-addonsCVE-2026-6020: ShopLentor custom-action callback permits arbitrary PHP function execution
ShopLentor through 3.3.7 exposes the woolentoropt/v1/custom-action REST endpoint to authenticated Administrators. Its handle_action() method passes the attacker-controlled callback parameter directly to call_user_func() without an allowlist. An Administrator can therefore invoke arbitrary callable PHP functions with potentially complete confidentiality, integrity and availability impact. The CNA does not disclose the HTTP method or supported callback arguments.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-6020
ShopLentor custom-action callback permits arbitrary PHP function execution
ShopLentor through 3.3.7 exposes the woolentoropt/v1/custom-action REST endpoint to authenticated Administrators. Its handle_action() method passes the attacker-controlled callback parameter directly to call_user_func() without an allowlist. An Administrator can therefore invoke arbitrary callable PHP functions with potentially complete confidentiality, integrity and availability impact. The CNA does not disclose the HTTP method or supported callback arguments.
|
> 3.3.7 |
CVE7.2
NVDPending
|
| Jul 28, 2026 |
CVE-2026-16811
ShopLentor administrators can inject SQL through abandoned-cart sorting
ShopLentor through 3.4.5 lets an Administrator supply the orderby parameter to GET /wp-json/woolentor/v1/abandoned-cart/carts. Cart_Data::get_abandoned_carts() passes that value to DB_Handler::get_abandoned_carts(), which interpolates it directly into the ORDER BY clause while $wpdb->prepare() protects only the separate value placeholders. An attacker with manage_options can therefore perform time-based SQL injection and extract database information.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Jul 28, 2026 |
CVE-2026-16797
ShopLentor contributors can read unintended WordPress option data
ShopLentor through 3.4.5 exposes GET /wp-json/woolentor/v1/get-wloptions to users who can edit_posts, including Contributors. After nonce validation, get_options_data() accepts attacker-controlled optionSection and optionKey values and passes them to woolentorBlocks_get_option(), which calls get_option(optionSection) and returns the selected nested value. This can disclose arbitrary wp_options records whose values use the expected array-of-arrays structure with title fields, including data belonging to other plugins.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Apr 14, 2026 |
CVE-2026-4059
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin: Cross-site scripting
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.5. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Feb 18, 2026 |
CVE-2026-1714
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution: A security weakness
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.6
NVDPending
|
| Nov 04, 2025 |
CVE-2025-12493
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor): Filesystem traversal
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Oct 25, 2025 |
CVE-2025-11823
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution: Cross-site scripting
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 25, 2025 |
CVE-2025-3775
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor): Server-side request forgery
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Sep 25, 2024 |
CVE-2024-8668
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor): Cross-site scripting
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 11, 2024 |
CVE-2024-5530
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor): Cross-site scripting
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 03, 2024 |
CVE-2024-34767
ShopLentor: Cross-site scripting
ShopLentor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| May 21, 2024 |
CVE-2024-4566
ShopLentor: A security weakness
ShopLentor is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.1
NVD7.1
|
| May 21, 2024 |
CVE-2024-3345
ShopLentor: Cross-site scripting
ShopLentor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 14, 2024 |
CVE-2023-6327
ShopLentor (formerly WooLentor): A security weakness
ShopLentor (formerly WooLentor) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Apr 09, 2024 |
CVE-2024-1960
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor): Cross-site scripting
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 04, 2024 |
CVE-2024-2868
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor): Cross-site scripting
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jul 17, 2023 |
CVE-2022-47172
Woolentor Addons: Cross-site request forgery
Woolentor Addons is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Mar 01, 2023 |
CVE-2022-46798
Woolentor Addons: Cross-site request forgery
Woolentor Addons is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.4
NVD5.4
|