ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

Vulnerabilities 26Slug woolentor-addonsLatest version 3.3.9WordPress.org →

Minimum safe version

3.3.6

Update to 3.3.6 or later to address 26 fixable vulnerabilities

Latest available3.3.9
N/A
2026-02-17< 3.3.3

ShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action

N/A
2026-04-13< 3.3.6

ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute

Critical 9.8
2025-11-04< 3.2.6

CVE-2025-12493

Medium 6.5
2025-04-25< 3.1.3

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter

Medium 6.4
2025-03-12< 3.1.1

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module

Medium 5.4
2024-05-03< 2.8.8

WordPress ShopLentor Plugin <= 2.8.7 is vulnerable to Cross Site Scripting (XSS)

N/A
2021-04-13< 1.8.6

WordPress WooLentor plugin <= 1.8.5 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities