Extension WordPress

Vulnérabilités ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

Cette page rassemble les failles publiées pour ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

26Vulnérabilités
2Critiques
26Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

26 fiches

CVE-2026-6287 Moyenne · 5,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor – WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId' block attribute in multiple Product Gride blocks in versions up to, and including, 3.3.8 due to insufficient…

Versions affectées

*-3.3.8

Correctif

3.3.9

Publication

26/05/2026

CVE-2026-4059 Moyenne · 6,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor <= 3.3.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute

The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentor_quickview_button shortcode's button_text attribute in all versions up to, and including, 3.3.5. This is due to insufficient input sanitization and missing output escaping on user-supplied…

Versions affectées

*-3.3.5

Correctif

3.3.6

Publication

13/04/2026

CVE-2026-1714 Élevée · 8,6
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor <= 3.3.2 – Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abuse in all versions up to, and including, 3.3.2 This is due to the…

Versions affectées

*-3.3.2

Correctif

3.3.3

Publication

17/02/2026

CVE-2025-12493 Critique · 9,8
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor <= 3.2.5 – Unauthenticated Local PHP File Inclusion via 'load_template'

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the 'load_template'…

Versions affectées

*-3.2.5

Correctif

3.2.6

Publication

03/11/2025

CVE-2025-11823 Moyenne · 6,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_exist_text' parameter in the 'wishsuite_button' shortcode in all versions up to,…

Versions affectées

*-3.2.4

Correctif

3.2.5

Publication

24/10/2025

CVE-2025-58990 Moyenne · 6,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor <= 3.2.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-3.2.0

Correctif

3.2.1

Publication

09/09/2025

CVE-2025-3775 Moyenne · 6,5
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 – Unauthenticated Server-Side Request Forgery via URL Parameter

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.2 via the woolentor_template_proxy…

Versions affectées

*-3.1.2

Correctif

3.1.3

Publication

24/04/2025

CVE-2025-1527 Moyenne · 6,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to a Stored DOM-Based Cross-Site Scripting via the plugin's Flash Sale Countdown module in all…

Versions affectées

*-3.1.0

Correctif

3.1.1

Publication

11/03/2025

CVE-2024-9538 Moyenne · 4,3
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor <= 2.9.8 – Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template

The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.8 via the 'render' function in includes/addons/wl_faq.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to…

Versions affectées

*-2.9.8

Correctif

2.9.9

Publication

10/10/2024

CVE-2024-8668 Moyenne · 6,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tooltip and countdown functionality in all versions up to,…

Versions affectées

*-2.9.7

Correctif

2.9.8

Publication

24/09/2024

CVE-2024-5530 Moyenne · 6,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via WL Product Horizontal Filter Widget

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's WL: Product Horizontal Filter widget in all versions…

Versions affectées

*-2.9.0

Correctif

2.9.1

Publication

10/06/2024

CVE-2024-4566 Élevée · 7,1
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor <= 2.8.8 – Missing Authorization to WordPress Option Modification

The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function in all versions up to, and including, 2.8.8. This makes it possible for authenticated attackers, with…

Versions affectées

*-2.8.8

Correctif

2.8.9

Publication

20/05/2024

CVE-2024-3345 Moyenne · 6,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor <= 2.8.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via woolentorsearch Shortcode

The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortcode in all versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

Versions affectées

*-2.8.8

Correctif

2.8.9

Publication

20/05/2024

CVE-2024-34767 Moyenne · 6,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor <= 2.8.7 – Authenticated (Contributor+) Stored Cross-Site Scripting

The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-2.8.7

Correctif

2.8.8

Publication

17/05/2024

CVE-2023-6327 Moyenne · 5,3
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor (formerly WooLentor) <= 2.8.7 – Missing Authorization via purchased_new_products

The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated…

Versions affectées

*-2.8.7

Correctif

2.8.8

Publication

03/05/2024

CVE-2024-3991 Moyenne · 6,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.7 – Authenticated (contributor+) Stored Cross-Site Scripting via _id

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute in the Horizontal Product Filter in all…

Versions affectées

*-2.8.7

Correctif

2.8.8

Publication

02/05/2024

CVE-2024-1057 Moyenne · 6,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) <= 2.8.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishsuite_button' shortcode in all versions up to, and…

Versions affectées

*-2.8.1

Correctif

2.8.2

Publication

19/04/2024

CVE-2023-7067 Moyenne · 4,3
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor <= 2.8.1 – Improper Authorization via woolentor_template_store

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woolentor_template_store' function…

Versions affectées

*-2.8.1

Correctif

2.8.2

Publication

18/04/2024

CVE-2024-2946 Moyenne · 6,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.4 – Authenticated (Contributor+) Stored Cross-site Scripting via QR Code Widget

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's QR Code Widget in all versions up to,…

Versions affectées

*-2.8.4

Correctif

2.8.5

Publication

04/04/2024

CVE-2024-2868 Moyenne · 6,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via WL Universal Product Layout

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slitems parameter in the WL Special Day Offer Widget…

Versions affectées

*-2.8.3

Correctif

2.8.4

Publication

03/04/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités