CVE-2026-4059: ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute
The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentorquickviewbutton shortcode's buttontext attribute in all versions up to, and including, 3.3.5. This is due to insufficient input sanitization and missing output escaping on user-supplied shortcode attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4059?
CVE-2026-4059 is categorized as a high severity vulnerability due to its potential for exploiting authenticated users.
How do I fix CVE-2026-4059?
To mitigate CVE-2026-4059, update the ShopLentor plugin to version 3.3.6 or later where the vulnerability has been addressed.
What type of vulnerability is CVE-2026-4059?
CVE-2026-4059 is identified as a Stored Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-4059?
All users of ShopLentor versions 3.3.5 and earlier are affected by CVE-2026-4059.
What can attackers do with CVE-2026-4059?
Attackers can exploit CVE-2026-4059 to inject malicious scripts into the website, affecting users who view compromised content.