CVE-2025-58990: WordPress ShopLentor Plugin <= 3.2.0 - Cross Site Scripting (XSS) Vulnerability
Published Sep 9, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems ShopLentor woolentor-addons allows Stored XSS.This issue affects ShopLentor: from n/a through <= 3.2.0.
Affected Software
3 affected components
HasTech ShopLentor<=3.2.0
WordPress ShopLentor Plugin<=3.2.0
HasThemes Shoplentor Wordpress<3.2.1
Remediation
Event History
Sep 9, 2025
CVE Published
via MITRE·04:33 PM
Data Sourced
via MITRE·04:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-58990?
CVE-2025-58990 is classified as a high severity vulnerability due to its potential for allowing stored cross-site scripting (XSS).
2
How do I fix CVE-2025-58990?
To fix CVE-2025-58990, update the ShopLentor plugin to version 3.2.1 or later where the vulnerability has been patched.
3
What versions of HasTech ShopLentor are affected by CVE-2025-58990?
CVE-2025-58990 affects all versions of HasTech ShopLentor from n/a up to and including version 3.2.0.
4
Is CVE-2025-58990 an issue for ShopLentor plugin used on WordPress?
Yes, CVE-2025-58990 also affects the WordPress ShopLentor Plugin up to version 3.2.0.
5
What type of vulnerability is CVE-2025-58990?
CVE-2025-58990 is a Stored Cross-Site Scripting (XSS) vulnerability.