ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
woolentor-addons · eklenti
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.
28 bilinen açık
2 kritik · son kayıt 18 Eyl 2026
Güvenlik açıkları
- Kritik 9.8
ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template'
- Kritik 9.8
CVE-2023-0232→ 2.5.4
ShopLentor < 2.5.4 - PHP Object Injection
- Yüksek 8.8
WordPress WooLentor Plugin <= 2.6.2 is vulnerable to Cross Site Request Forgery (CSRF)
- Yüksek 8.6
ShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action
- Yüksek 7.2
ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API
- Yüksek 7.1
ShopLentor <= 2.8.8 - Missing Authorization to WordPress Option Modification
- Orta 6.5
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request
- Orta 6.5
ShopLentor <= 2.9.8 - Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template
- Orta 6.4
ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute
- Orta 6.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.3 - Authenticated (Contributor+) Stored
- Orta 6.1
ShopLentor <= 3.5.1 - Reflected Cross-Site Scripting via Query-String Parameter Name
- Orta 5.4
ShopLentor - WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Bl
- Orta 5.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
- Orta 5.4
WordPress ShopLentor Plugin <= 3.2.0 - Cross Site Scripting (XSS) Vulnerability
- Orta 5.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored
- Orta 5.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 - Authenticated (Contributor+) DOM-Ba
- Orta 5.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.0 - Authenticated (Contributor+) Stored
- Orta 5.4
WordPress ShopLentor plugin <= 2.8.7 - Cross Site Scripting (XSS) vulnerability
- Orta 5.4
ShopLentor <= 2.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via woolentorsearch Shortcode
- Orta 5.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.7 - Authenticated (contributor+) Stored
- Orta 5.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) <= 2.8.1 - Authenticated (Contributor+) Stored
- Orta 5.4
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.4 - Authenticated (Contributor+) Stored
- Orta 5.4
ShopLentor <= 2.8.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Banner Link
- Orta 5.4
WordPress WooLentor Plugin <= 2.5.1 is vulnerable to Cross Site Request Forgery (CSRF)
- Orta 5.3
ShopLentor (formerly WooLentor) <= 2.8.7 - Missing Authorization via purchased_new_products
- Orta 4.9
ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
- Orta 4.3
ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter
- Orta 4.3
ShopLentor <= 2.8.1 - Improper Authorization via woolentor_template_store