Extension WordPress

Vulnérabilités ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin, page 2

Cette page rassemble les failles publiées pour ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

26Vulnérabilités
2Critiques
26Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

26 fiches

CVE-2024-1960 Moyenne · 6,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor <= 2.8.1 – Authenticated(Contributor+) Stored Cross-Site Scripting via Banner Link

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Special Offer Day Widget Banner Link in all versions…

Versions affectées

*-2.8.1

Correctif

2.8.2

Publication

14/03/2024

CVE-2022-47172 Moyenne · 4,3
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

WooLentor <= 2.6.2 – Cross-Site Request Forgery via process_data

The WooLentor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation on the process_data function. This makes it possible for unauthenticated attackers…

Versions affectées

*-2.6.2

Correctif

2.6.3

Publication

05/07/2023

CVE-2022-46798 Moyenne · 5,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor <= 2.5.1 – Cross-Site Request Forgery to Post Updates

The ShopLentor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on the 'templates_ajax_request' function. This makes it possible for unauthenticated attackers…

Versions affectées

*-2.5.1

Correctif

2.5.2

Publication

06/02/2023

CVE-2023-0231 Moyenne · 6,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

WooLentor <= 2.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The WooLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 2.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

Versions affectées

*-2.5.3

Correctif

2.5.4

Publication

28/01/2023

CVE-2023-0232 Critique · 9,8
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

WooLentor <= 2.5.3 – PHP Object Injection

The WooLentor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.3 via deserialization of untrusted input in the function woolentor_set_views_count, which unserializes a user-provided cookie. This allows unauthenticated attackers to inject…

Versions affectées

*-2.5.3

Correctif

2.5.4

Publication

28/01/2023

CVE-2021-24262 Moyenne · 6,4
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

WooLentor – WooCommerce Elementor Addons + Builder <= 1.8.5 – Authenticated Stored Cross-Site Scripting

The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

Versions affectées

[*, 1.8.6)

Correctif

1.8.6

Publication

13/04/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités