Cross-Site Scripting
16 records57.1%First: 2021. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 28 vulnerability records associated with ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin, published between 2021 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2021 | 1 | |
| 2023 | 4 | |
| 2024 | 13 | |
| 2025 | 5 | |
| 2026 | 5 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 7.1% |
| High | 2 | 7.1% |
| Medium | 24 | 85.7% |
First: 2021. Latest: 2026.
First: 2024. Latest: 2026.
First: 2023. Latest: 2026.
First: 2023. Latest: 2023.
First: 2024. Latest: 2024.
First: 2025. Latest: 2025.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.4.63.3.93.3.63.3.33.2.63.2.53.2.13.1.33.1.12.9.92.9.82.9.12.8.92.8.82.8.52.8.42.8.22.6.32.5.22.5.41.8.6Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-2.5.3 | WooLentor <= 2.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | January 28, 2023 | 2.5.4 | Medium |
*-2.5.3 | WooLentor <= 2.5.3 - PHP Object Injection | January 28, 2023 | 2.5.4 | Critical |
[*, 1.8.6) | WooLentor – WooCommerce Elementor Addons + Builder <= 1.8.5 - Authenticated Stored Cross-Site Scripting | April 13, 2021 | 1.8.6 | Medium |
Selected source records
Published: July 27, 2026
Published: July 27, 2026
Published: May 26, 2026
Published: April 13, 2026
Published: February 17, 2026
Published: November 3, 2025
Published: October 24, 2025
Published: September 9, 2025
Published: November 3, 2025
Published: January 28, 2023
Published: February 17, 2026
Published: May 20, 2024
Published: April 24, 2025
Published: April 3, 2024
Published: October 24, 2025
Published: April 13, 2021
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.