ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
woolentor-addons · plugin
Known security vulnerabilities for ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin. Find out in seconds which version runs on your site with WP Lens.
28 known vulnerabilities
2 critical · latest Sep 18, 2026
Vulnerabilities
- Critical 9.8
ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template'
- Critical 9.8
CVE-2023-0232→ 2.5.4
ShopLentor < 2.5.4 - PHP Object Injection
- High 8.8
WordPress WooLentor Plugin <= 2.6.2 is vulnerable to Cross Site Request Forgery (CSRF)
- High 8.6
ShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action
- High 7.2
ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API
- High 7.1
ShopLentor <= 2.8.8 - Missing Authorization to WordPress Option Modification
- Medium 6.5
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request
- Medium 6.5
ShopLentor <= 2.9.8 - Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template
- Medium 6.4
ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute
- Medium 6.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.3 - Authenticated (Contributor+) Stored
- Medium 6.1
ShopLentor <= 3.5.1 - Reflected Cross-Site Scripting via Query-String Parameter Name
- Medium 5.4
ShopLentor - WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Bl
- Medium 5.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
- Medium 5.4
WordPress ShopLentor Plugin <= 3.2.0 - Cross Site Scripting (XSS) Vulnerability
- Medium 5.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored
- Medium 5.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 - Authenticated (Contributor+) DOM-Ba
- Medium 5.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.0 - Authenticated (Contributor+) Stored
- Medium 5.4
WordPress ShopLentor plugin <= 2.8.7 - Cross Site Scripting (XSS) vulnerability
- Medium 5.4
ShopLentor <= 2.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via woolentorsearch Shortcode
- Medium 5.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.7 - Authenticated (contributor+) Stored
- Medium 5.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) <= 2.8.1 - Authenticated (Contributor+) Stored
- Medium 5.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.4 - Authenticated (Contributor+) Stored
- Medium 5.4
ShopLentor <= 2.8.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Banner Link
- Medium 5.4
WordPress WooLentor Plugin <= 2.5.1 is vulnerable to Cross Site Request Forgery (CSRF)
- Medium 5.3
ShopLentor (formerly WooLentor) <= 2.8.7 - Missing Authorization via purchased_new_products
- Medium 4.9
ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
- Medium 4.3
ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter
- Medium 4.3
ShopLentor <= 2.8.1 - Improper Authorization via woolentor_template_store