Extension WordPress
Vulnérabilités ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin, page 2
Cette page rassemble les failles publiées pour ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
26 fiches
ShopLentor <= 2.8.1 – Authenticated(Contributor+) Stored Cross-Site Scripting via Banner Link
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Special Offer Day Widget Banner Link in all versions…
*-2.8.1
2.8.2
14/03/2024
WooLentor <= 2.6.2 – Cross-Site Request Forgery via process_data
The WooLentor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation on the process_data function. This makes it possible for unauthenticated attackers…
*-2.6.2
2.6.3
05/07/2023
ShopLentor <= 2.5.1 – Cross-Site Request Forgery to Post Updates
The ShopLentor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on the 'templates_ajax_request' function. This makes it possible for unauthenticated attackers…
*-2.5.1
2.5.2
06/02/2023
WooLentor <= 2.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The WooLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 2.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
*-2.5.3
2.5.4
28/01/2023
WooLentor <= 2.5.3 – PHP Object Injection
The WooLentor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.3 via deserialization of untrusted input in the function woolentor_set_views_count, which unserializes a user-provided cookie. This allows unauthenticated attackers to inject…
*-2.5.3
2.5.4
28/01/2023
WooLentor – WooCommerce Elementor Addons + Builder <= 1.8.5 – Authenticated Stored Cross-Site Scripting
The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
[*, 1.8.6)
1.8.6
13/04/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.