Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 28 vulnerability records associated with ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin, published between 2021 and 2026.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

28Total records
2Critical
2High
24Medium
0Low
0Informational
28Patched records
0Currently marked unpatched
2021-04-13First disclosure
2026-07-27Latest disclosure
28 of 28CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
202111 records
202344 records
20241313 records
202555 records
202655 records

Severity Breakdown

SeverityRecordsShare
Critical27.1%
High27.1%
Medium2485.7%

Vulnerability-Type Breakdown

Cross-Site Scripting

16 records57.1%

First: 2021. Latest: 2026.

Missing Authorization

4 records14.3%

First: 2024. Latest: 2026.

Other

3 records10.7%

First: 2023. Latest: 2026.

CSRF

2 records7.1%

First: 2023. Latest: 2023.

Information Disclosure

1 record3.6%

First: 2024. Latest: 2024.

Path Traversal

1 record3.6%

First: 2025. Latest: 2025.

SQL Injection

1 record3.6%

First: 2026. Latest: 2026.

Patch Status

Patched
28
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 3.4.6
  • 3.3.9
  • 3.3.6
  • 3.3.3
  • 3.2.6
  • 3.2.5
  • 3.2.1
  • 3.1.3
  • 3.1.1
  • 2.9.9
  • 2.9.8
  • 2.9.1
  • 2.8.9
  • 2.8.8
  • 2.8.5
  • 2.8.4
  • 2.8.2
  • 2.6.3
  • 2.5.2
  • 2.5.4
  • 1.8.6

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-3.4.5ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' ParameterJuly 27, 20263.4.6Medium
*-3.4.5ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' ParameterJuly 27, 20263.4.6Medium
*-3.3.8ShopLentor - WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block AttributeMay 26, 20263.3.9Medium
*-3.3.5ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode AttributeApril 13, 20263.3.6Medium
*-3.3.2ShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX ActionFebruary 17, 20263.3.3High
*-3.2.5ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template'November 3, 20253.2.6Critical
*-3.2.4ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeOctober 24, 20253.2.5Medium
*-3.2.0ShopLentor <= 3.2.0 - Authenticated (Contributor+) Stored Cross-Site ScriptingSeptember 9, 20253.2.1Medium
*-3.1.2ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL ParameterApril 24, 20253.1.3Medium
*-3.1.0ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown ModuleMarch 11, 20253.1.1Medium
*-2.9.8ShopLentor <= 2.9.8 - Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor TemplateOctober 10, 20242.9.9Medium
*-2.9.7ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site ScriptingSeptember 24, 20242.9.8Medium
*-2.9.0ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Product Horizontal Filter WidgetJune 10, 20242.9.1Medium
*-2.8.8ShopLentor <= 2.8.8 - Missing Authorization to WordPress Option ModificationMay 20, 20242.8.9High
*-2.8.8ShopLentor <= 2.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via woolentorsearch ShortcodeMay 20, 20242.8.9Medium
*-2.8.7ShopLentor <= 2.8.7 - Authenticated (Contributor+) Stored Cross-Site ScriptingMay 17, 20242.8.8Medium
*-2.8.7ShopLentor (formerly WooLentor) <= 2.8.7 - Missing Authorization via purchased_new_productsMay 3, 20242.8.8Medium
*-2.8.7ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.7 - Authenticated (contributor+) Stored Cross-Site Scripting via _idMay 2, 20242.8.8Medium
*-2.8.1ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site ScriptingApril 19, 20242.8.2Medium
*-2.8.1ShopLentor <= 2.8.1 - Improper Authorization via woolentor_template_storeApril 18, 20242.8.2Medium
*-2.8.4ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.4 - Authenticated (Contributor+) Stored Cross-site Scripting via QR Code WidgetApril 4, 20242.8.5Medium
*-2.8.3ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Universal Product LayoutApril 3, 20242.8.4Medium
*-2.8.1ShopLentor <= 2.8.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Banner LinkMarch 14, 20242.8.2Medium
*-2.6.2WooLentor <= 2.6.2 - Cross-Site Request Forgery via process_dataJuly 5, 20232.6.3Medium
*-2.5.1ShopLentor <= 2.5.1 - Cross-Site Request Forgery to Post UpdatesFebruary 6, 20232.5.2Medium

Selected source records

Latest Records

MediumCVE-2026-16797

ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter

Published: July 27, 2026

Affected versions
*-3.4.5
Patched versions
3.4.6
Original Wordfence record
MediumCVE-2026-16811

ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter

Published: July 27, 2026

Affected versions
*-3.4.5
Patched versions
3.4.6
Original Wordfence record
MediumCVE-2026-6287

ShopLentor - WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute

Published: May 26, 2026

Affected versions
*-3.3.8
Patched versions
3.3.9
Original Wordfence record
MediumCVE-2026-4059

ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute

Published: April 13, 2026

Affected versions
*-3.3.5
Patched versions
3.3.6
Original Wordfence record
HighCVE-2026-1714

ShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action

Published: February 17, 2026

Affected versions
*-3.3.2
Patched versions
3.3.3
Original Wordfence record
CriticalCVE-2025-12493

ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template'

Published: November 3, 2025

Affected versions
*-3.2.5
Patched versions
3.2.6
Original Wordfence record
MediumCVE-2025-11823

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Published: October 24, 2025

Affected versions
*-3.2.4
Patched versions
3.2.5
Original Wordfence record
MediumCVE-2025-58990

ShopLentor <= 3.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Published: September 9, 2025

Affected versions
*-3.2.0
Patched versions
3.2.1
Original Wordfence record

Highest-Severity Records

CriticalCVE-2025-12493

ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template'

Published: November 3, 2025

Affected versions
*-3.2.5
Patched versions
3.2.6
Original Wordfence record
CriticalCVE-2023-0232

WooLentor <= 2.5.3 - PHP Object Injection

Published: January 28, 2023

Affected versions
*-2.5.3
Patched versions
2.5.4
Original Wordfence record
HighCVE-2026-1714

ShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action

Published: February 17, 2026

Affected versions
*-3.3.2
Patched versions
3.3.3
Original Wordfence record
HighCVE-2024-4566

ShopLentor <= 2.8.8 - Missing Authorization to WordPress Option Modification

Published: May 20, 2024

Affected versions
*-2.8.8
Patched versions
2.8.9
Original Wordfence record
MediumCVE-2025-3775

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter

Published: April 24, 2025

Affected versions
*-3.1.2
Patched versions
3.1.3
Original Wordfence record
MediumCVE-2024-2868

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Universal Product Layout

Published: April 3, 2024

Affected versions
*-2.8.3
Patched versions
2.8.4
Original Wordfence record
MediumCVE-2025-11823

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Published: October 24, 2025

Affected versions
*-3.2.4
Patched versions
3.2.5
Original Wordfence record
MediumCVE-2021-24262

WooLentor – WooCommerce Elementor Addons + Builder <= 1.8.5 - Authenticated Stored Cross-Site Scripting

Published: April 13, 2021

Affected versions
[*, 1.8.6)
Patched versions
1.8.6
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory