ShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
Minimum safe version
3.3.6
Update to 3.3.6 or later to address 26 fixable vulnerabilities
ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute
CVE-2025-12493
CVE-2025-11823
CVE-2025-58990
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module
CVE-2024-9538
CVE-2024-8668
CVE-2024-5530
CVE-2024-3345
CVE-2024-4566
CVE-2024-34767
CVE-2023-6327
WordPress ShopLentor Plugin <= 2.8.7 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-1057
CVE-2023-7067
CVE-2024-2946
CVE-2024-2868
CVE-2024-1960
CVE-2022-47172
CVE-2022-46798
CVE-2023-0231
CVE-2023-0232
WordPress WooLentor plugin <= 1.8.5 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
CVE-2021-24262