📦 Shoplentor

by Hasthemes

🔍 What is Shoplentor?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-12493

CRITICAL CVSS 9.8 Nov 4, 2025

This vulnerability allows unauthenticated attackers to include and execute arbitrary PHP files on WordPress servers running the ShopLentor plugin. Attackers can achieve remote code execution, bypass a...

CVE-2023-0232

CRITICAL CVSS 9.8 Feb 21, 2023

The ShopLentor (WooLentor) WordPress plugin before version 2.5.4 contains a PHP Object Injection vulnerability due to unsafe unserialization of user-controlled cookie data. This allows unauthenticated...

CVE-2025-11823

MEDIUM CVSS 6.4 Oct 25, 2025

This stored XSS vulnerability in the ShopLentor WooCommerce Builder plugin allows authenticated attackers with Contributor access or higher to inject malicious scripts into WordPress pages. When users...

CVE-2025-58990

MEDIUM CVSS 6.5 Sep 9, 2025

This stored cross-site scripting (XSS) vulnerability in the ShopLentor WordPress plugin allows attackers to inject malicious scripts into web pages that are then executed when other users view those p...

CVE-2024-9538

MEDIUM CVSS 4.3 Oct 11, 2024

The ShopLentor (WooLentor) WordPress plugin has an information disclosure vulnerability that allows authenticated attackers with Contributor-level access or higher to view private, pending, and draft ...

CVE-2023-6327

MEDIUM CVSS 5.3 May 14, 2024

The ShopLentor (formerly WooLentor) WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to view all products purchased in the past week along with purchase...

CVE-2024-3991

MEDIUM CVSS 6.4 May 2, 2024

This stored XSS vulnerability in the ShopLentor WordPress plugin allows authenticated attackers with contributor-level access or higher to inject malicious scripts into web pages. When users visit com...