VendorsHasThemesshoplentorany version
Vulnerabilities

HasThemes ShopLentor any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2023-0232
ShopLentor < 2.5.4 - PHP Object Injection
Published 2023-02-21 · Modified
9.8EPSS 0.033
CVE-2025-12493
ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template'
Published 2025-11-04 · Analyzed
9.8EPSS 0.008
CVE-2024-4566
ShopLentor <= 2.8.8 - Missing Authorization to WordPress Option Modification
Published 2024-05-21 · Modified
7.1EPSS 0.004
CVE-2024-9538
ShopLentor <= 2.9.8 - Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template
Published 2024-10-11 · Analyzed
6.5EPSS 0.004
CVE-2025-3775
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter
Published 2025-04-25 · Analyzed
6.5EPSS 0.003
CVE-2024-34767
WordPress ShopLentor plugin <= 2.8.7 - Cross Site Scripting (XSS) vulnerability
Published 2024-06-03 · Analyzed
6.5EPSS 0.003
CVE-2025-58990
WordPress ShopLentor Plugin <= 3.2.0 - Cross Site Scripting (XSS) Vulnerability
Published 2025-09-09 · Modified
6.5EPSS 0.002
CVE-2024-1960
ShopLentor <= 2.8.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Banner Link
Published 2024-04-09 · Modified
6.4EPSS 0.005
CVE-2024-2868
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Universal Product Layout
Published 2024-04-04 · Modified
6.4EPSS 0.005
CVE-2024-3991
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.7 - Authenticated (contributor+) Stored Cross-Site Scripting via _id
Published 2024-05-02 · Modified
6.4EPSS 0.004
CVE-2024-5530
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Product Horizontal Filter Widget
Published 2024-06-11 · Modified
6.4EPSS 0.004
CVE-2024-3345
ShopLentor <= 2.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via woolentorsearch Shortcode
Published 2024-05-21 · Modified
6.4EPSS 0.004
CVE-2024-2946
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.4 - Authenticated (Contributor+) Stored Cross-site Scripting via QR Code Widget
Published 2024-04-09 · Modified
6.4EPSS 0.003
CVE-2024-1057
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-04-20 · Modified
6.4EPSS 0.003
CVE-2025-1527
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module
Published 2025-03-12 · Analyzed
6.4EPSS 0.003
CVE-2025-11823
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2025-10-25 · Analyzed
6.4EPSS 0.002
CVE-2023-0231
ShopLentor < 2.5.4 - Contributor+ Stored XSS
Published 2023-02-21 · Modified
5.4EPSS 0.005
CVE-2023-6327
ShopLentor (formerly WooLentor) <= 2.8.7 - Missing Authorization via purchased_new_products
Published 2024-05-09 · Modified
5.3EPSS 0.007
CVE-2023-7067
ShopLentor <= 2.8.1 - Improper Authorization via woolentor_template_store
Published 2024-05-02 · Modified
4.3EPSS 0.003