← WordPress Vulnerabilities
WordPress security by component

ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin is a WordPress component with 17 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: woolentor-addons

CVE-2026-16811: ShopLentor administrators can inject SQL through abandoned-cart sorting

ShopLentor through 3.4.5 lets an Administrator supply the orderby parameter to GET /wp-json/woolentor/v1/abandoned-cart/carts. Cart_Data::get_abandoned_carts() passes that value to DB_Handler::get_abandoned_carts(), which interpolates it directly into the ORDER BY clause while $wpdb->prepare() protects only the separate value placeholders. An attacker with manage_options can therefore perform time-based SQL injection and extract database information.

PublishedJul 28, 2026
Known safe version> 3.4.5
Safe version
Jul 28, 2026 CVE-2026-16811
ShopLentor administrators can inject SQL through abandoned-cart sorting
ShopLentor through 3.4.5 lets an Administrator supply the orderby parameter to GET /wp-json/woolentor/v1/abandoned-cart/carts. Cart_Data::get_abandoned_carts() passes that value to DB_Handler::get_abandoned_carts(), which interpolates it directly into the ORDER BY clause while $wpdb->prepare() protects only the separate value placeholders. An attacker with manage_options can therefore perform time-based SQL injection and extract database information.
> 3.4.5
CVE4.9
NVDPending
Jul 28, 2026 CVE-2026-16797
ShopLentor contributors can read unintended WordPress option data
ShopLentor through 3.4.5 exposes GET /wp-json/woolentor/v1/get-wloptions to users who can edit_posts, including Contributors. After nonce validation, get_options_data() accepts attacker-controlled optionSection and optionKey values and passes them to woolentorBlocks_get_option(), which calls get_option(optionSection) and returns the selected nested value. This can disclose arbitrary wp_options records whose values use the expected array-of-arrays structure with title fields, including data belonging to other plugins.
> 3.4.5
CVE4.3
NVDPending
Apr 14, 2026 CVE-2026-4059
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin: Cross-site scripting
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.5.
> 3.3.5
CVE6.4
NVDPending
Feb 18, 2026 CVE-2026-1714
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution: A security weakness
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.6
NVDPending
Nov 04, 2025 CVE-2025-12493
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor): Filesystem traversal
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE9.8
NVDPending
Oct 25, 2025 CVE-2025-11823
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution: Cross-site scripting
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 25, 2025 CVE-2025-3775
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor): Server-side request forgery
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE6.5
NVDPending
Sep 25, 2024 CVE-2024-8668
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor): Cross-site scripting
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 11, 2024 CVE-2024-5530
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor): Cross-site scripting
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 03, 2024 CVE-2024-34767
ShopLentor: Cross-site scripting
ShopLentor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
May 21, 2024 CVE-2024-4566
ShopLentor: A security weakness
ShopLentor is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.1
NVD7.1
May 21, 2024 CVE-2024-3345
ShopLentor: Cross-site scripting
ShopLentor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 14, 2024 CVE-2023-6327
ShopLentor (formerly WooLentor): A security weakness
ShopLentor (formerly WooLentor) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Apr 09, 2024 CVE-2024-1960
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor): Cross-site scripting
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 04, 2024 CVE-2024-2868
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor): Cross-site scripting
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Jul 17, 2023 CVE-2022-47172
Woolentor Addons: Cross-site request forgery
Woolentor Addons is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Mar 01, 2023 CVE-2022-46798
Woolentor Addons: Cross-site request forgery
Woolentor Addons is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD5.4