Cross-Site Scripting
16 records57.1%First: 2021. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 28 vulnerability records associated with ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin, published between 2021 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2021 | 1 | |
| 2023 | 4 | |
| 2024 | 13 | |
| 2025 | 5 | |
| 2026 | 5 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 7.1% |
| High | 2 | 7.1% |
| Medium | 24 | 85.7% |
First: 2021. Latest: 2026.
First: 2024. Latest: 2026.
First: 2023. Latest: 2026.
First: 2023. Latest: 2023.
First: 2024. Latest: 2024.
First: 2025. Latest: 2025.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.4.63.3.93.3.63.3.33.2.63.2.53.2.13.1.33.1.12.9.92.9.82.9.12.8.92.8.82.8.52.8.42.8.22.6.32.5.22.5.41.8.6Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.4.5 | ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter | July 27, 2026 | 3.4.6 | Medium |
*-3.4.5 | ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter | July 27, 2026 | 3.4.6 | Medium |
*-3.3.8 | ShopLentor - WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute | May 26, 2026 | 3.3.9 | Medium |
*-3.3.5 | ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute | April 13, 2026 | 3.3.6 | Medium |
*-3.3.2 | ShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action | February 17, 2026 | 3.3.3 | High |
*-3.2.5 | ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template' | November 3, 2025 | 3.2.6 | Critical |
*-3.2.4 | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | October 24, 2025 | 3.2.5 | Medium |
*-3.2.0 | ShopLentor <= 3.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | September 9, 2025 | 3.2.1 | Medium |
*-3.1.2 | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter | April 24, 2025 | 3.1.3 | Medium |
*-3.1.0 | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module | March 11, 2025 | 3.1.1 | Medium |
*-2.9.8 | ShopLentor <= 2.9.8 - Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template | October 10, 2024 | 2.9.9 | Medium |
*-2.9.7 | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | September 24, 2024 | 2.9.8 | Medium |
*-2.9.0 | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Product Horizontal Filter Widget | June 10, 2024 | 2.9.1 | Medium |
*-2.8.8 | ShopLentor <= 2.8.8 - Missing Authorization to WordPress Option Modification | May 20, 2024 | 2.8.9 | High |
*-2.8.8 | ShopLentor <= 2.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via woolentorsearch Shortcode | May 20, 2024 | 2.8.9 | Medium |
*-2.8.7 | ShopLentor <= 2.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | May 17, 2024 | 2.8.8 | Medium |
*-2.8.7 | ShopLentor (formerly WooLentor) <= 2.8.7 - Missing Authorization via purchased_new_products | May 3, 2024 | 2.8.8 | Medium |
*-2.8.7 | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.7 - Authenticated (contributor+) Stored Cross-Site Scripting via _id | May 2, 2024 | 2.8.8 | Medium |
*-2.8.1 | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | April 19, 2024 | 2.8.2 | Medium |
*-2.8.1 | ShopLentor <= 2.8.1 - Improper Authorization via woolentor_template_store | April 18, 2024 | 2.8.2 | Medium |
*-2.8.4 | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.4 - Authenticated (Contributor+) Stored Cross-site Scripting via QR Code Widget | April 4, 2024 | 2.8.5 | Medium |
*-2.8.3 | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Universal Product Layout | April 3, 2024 | 2.8.4 | Medium |
*-2.8.1 | ShopLentor <= 2.8.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Banner Link | March 14, 2024 | 2.8.2 | Medium |
*-2.6.2 | WooLentor <= 2.6.2 - Cross-Site Request Forgery via process_data | July 5, 2023 | 2.6.3 | Medium |
*-2.5.1 | ShopLentor <= 2.5.1 - Cross-Site Request Forgery to Post Updates | February 6, 2023 | 2.5.2 | Medium |
Selected source records
Published: July 27, 2026
Published: July 27, 2026
Published: May 26, 2026
Published: April 13, 2026
Published: February 17, 2026
Published: November 3, 2025
Published: October 24, 2025
Published: September 9, 2025
Published: November 3, 2025
Published: January 28, 2023
Published: February 17, 2026
Published: May 20, 2024
Published: April 24, 2025
Published: April 3, 2024
Published: October 24, 2025
Published: April 13, 2021
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.