SecAlerts
S

ShopLentor

Security Risk Profile

41
/100
medium

Security Risk Score

Comprehensive risk assessment based on 17 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 4, 2024 to present

17
Total CVEs
2
Critical+High
0
Exploited
2
Unpatched

Threat Assessment

Avg CVSS
6.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
41/100
medium

Severity Distribution

Critical
1
High
1
Medium
15
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
XSS
10
2
Path Traversal
1
3
SSRF
1
4
Infoleak
1

Most Affected Products

1. HasThemes Shoplentor Wordpress15
2. ShopLentor ShopLentor7
3. ShopLentor WooLentor4
4. ShopLentor WooCommerce Builder for Elementor & Gutenberg3
5. ShopLentor ShopLentor - WooCommerce Builder for Elementor & Gutenberg1

Recent Vulnerabilities

See more →
CVE-2026-6287
CVSS 5.4medium

ShopLentor - WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute

May 27, 2026🔧 No Patch
CVE-2026-4059
CVSS 6.4medium

ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute

Apr 14, 2026🔧 No Patch
CVE-2025-12493
CVSS 9.8critical

ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template'

Nov 4, 2025🔧 No Patch
CVE-2025-11823
CVSS 6.4medium

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Oct 25, 2025🔧 No Patch
CVE-2025-3775
CVSS 6.5EPSS 0%medium

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter

Apr 25, 2025🔧 No Patch
CVE-2025-1527
CVSS 6.4medium

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module

Mar 12, 2025
CVE-2024-9538
CVSS 6.5EPSS 0%medium

ShopLentor <= 2.9.8 - Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template

Oct 11, 2024🔧 No Patch
CVE-2024-5530
CVSS 6.4EPSS 0%medium

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Product Horizontal Filter Widget

Jun 11, 2024🔧 No Patch
CVE-2024-4566
CVSS 7.1EPSS 0%high

ShopLentor <= 2.8.8 - Missing Authorization to WordPress Option Modification

May 21, 2024🔧 No Patch
CVE-2024-3345
CVSS 6.4medium

ShopLentor <= 2.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via woolentorsearch Shortcode

May 21, 2024

Monitor ShopLentor in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

ShopLentor Security Vulnerabilities & Risk Score | 17 CVEs | SecAlerts - SecAlerts