Hasthemes
Hasthemes Shoplentor: vulnerabilidades y CVE
Hasthemes Shoplentor tiene 26 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses9
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-92554 | Media (6.1) | 0.37% | — | 18 sept 2026 | The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query-String Parameter Name in all versions up to, and including, 3.5.1… |
| CVE-2026-6020 | Alta (7.2) | 0.78% | — | 5 ago 2026 | The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint in all versions up to, and including, 3.3.7. This is due to the handle_action()… |
| CVE-2026-16811 | Media (4.9) | 0.44% | — | 28 jul 2026 | The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.4.5 due to… |
| CVE-2026-16797 | Media (4.3) | 0.38% | — | 28 jul 2026 | The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.5 via the 'optionSection'… |
| CVE-2026-6287 | Media (5.4) | 0.24% | — | 27 may 2026 | The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId' block attribute in multiple Product Gride blocks in versions up to,… |
| CVE-2026-4059 | Media (6.4) | 0.35% | — | 14 abr 2026 | The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentor_quickview_button shortcode's button_text attribute in all versions up to, and including, 3.3.5. This is due to… |
| CVE-2026-1714 | Alta (8.6) | 0.67% | — | 18 feb 2026 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abuse in all versions up to, and including, 3.3.2. This is due to the… |
| CVE-2025-12493 | Crítica (9.8) | 0.81% | — | 4 nov 2025 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including,… |
| CVE-2025-11823 | Media (5.4) | 0.22% | — | 25 oct 2025 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_exist_text' parameter in the… |
| CVE-2025-58990 | Media (5.4) | 0.17% | — | 9 sept 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems ShopLentor woolentor-addons allows Stored XSS.This issue affects ShopLentor: from n/a through <= 3.2.0. |
| CVE-2025-3775 | Media (6.5) | 0.28% | — | 25 abr 2025 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and… |
| CVE-2025-1527 | Media (5.4) | 0.26% | — | 12 mar 2025 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to a Stored DOM-Based Cross-Site Scripting via the plugin's Flash… |
| CVE-2024-9538 | Media (6.5) | 0.40% | — | 11 oct 2024 | The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.8 via the 'render' function in includes/addons/wl_faq.php. This makes it possible for… |
| CVE-2024-5530 | Media (5.4) | 0.38% | — | 11 jun 2024 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's WL: Product… |
| CVE-2024-34767 | Media (5.4) | 0.26% | — | 3 jun 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes ShopLentor allows Stored XSS.This issue affects ShopLentor: from n/a through 2.8.7. |
| CVE-2024-4566 | Alta (7.1) | 0.41% | — | 21 may 2024 | The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function in all versions up to, and including, 2.8.8. This makes it possible… |
| CVE-2024-3345 | Media (5.4) | 0.36% | — | 21 may 2024 | The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortcode in all versions up to, and including, 2.8.8 due to insufficient input sanitization and output… |
| CVE-2023-6327 | Media (5.3) | 0.67% | — | 14 may 2024 | The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in all versions up to, and including, 2.8.7.… |
| CVE-2024-3991 | Media (5.4) | 0.42% | — | 2 may 2024 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute in the… |
| CVE-2023-7067 | Media (4.3) | 0.34% | — | 2 may 2024 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… |
| CVE-2024-1057 | Media (5.4) | 0.32% | — | 20 abr 2024 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishsuite_button'… |
| CVE-2024-2946 | Media (5.4) | 0.34% | — | 9 abr 2024 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's QR Code Widget in… |
| CVE-2024-1960 | Media (5.4) | 0.52% | — | 9 abr 2024 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Special Offer Day Widget… |
| CVE-2024-2868 | Media (6.4) | 0.45% | — | 4 abr 2024 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slitems parameter in the WL… |
| CVE-2023-0232 | Crítica (9.8) | 3.3% | — | 21 feb 2023 | The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection. |
| CVE-2023-0231 | Media (5.4) | 0.53% | — | 21 feb 2023 | The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Hasthemes
HT Mega · 31Wishsuite · 5Extensions FOR CF7 · 5Woolentor - Woocommerce Elementor Addons + Builder · 4HT Event · 3HT Slider FOR Elementor · 3HT Feed · 3Download Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks · 3WC Builder · 3Swatchly · 2HT Easy GA4 (google Analytics 4) · 2HT Menu · 2