Known vulnerabilities in the Shoplentor plugin
21 security advisories have been published for the Shoplentor plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Shoplentor - Security Vulnerability (CVE-2026-6020) HIGH
- ShopLentor - Cross-Site Scripting (XSS) (CVE-2026-6287) MEDIUM
- ShopLentor - Cross-Site Scripting (XSS) (CVE-2026-4059) MEDIUM
- ShopLentor - Security Vulnerability (CVE-2026-1714) HIGH
- Shoplentor - Path Traversal (CVE-2025-12493) CRITICAL
- Shoplentor - Cross-Site Scripting (XSS) (CVE-2025-11823) MEDIUM
- Shoplentor - Server-Side Request Forgery (SSRF) (CVE-2025-3775) MEDIUM
- Shoplentor - Cross-Site Scripting (XSS) (CVE-2025-1527) MEDIUM
- Shoplentor - Information Disclosure (CVE-2024-9538) MEDIUM
- Shoplentor - Cross-Site Scripting (XSS) (CVE-2024-5530) MEDIUM
- Shoplentor - Broken Access Control (CVE-2024-4566) HIGH
- Shoplentor - Cross-Site Scripting (XSS) (CVE-2024-3345) MEDIUM
- Shoplentor - Broken Access Control (CVE-2023-6327) MEDIUM
- Shoplentor - Cross-Site Scripting (XSS) (CVE-2024-3991) MEDIUM
- Shoplentor - Broken Access Control (CVE-2023-7067) MEDIUM
- Shoplentor - Cross-Site Scripting (XSS) (CVE-2024-1057) MEDIUM
- Shoplentor - Cross-Site Scripting (XSS) (CVE-2024-2946) MEDIUM
- Shoplentor - Cross-Site Scripting (XSS) (CVE-2024-1960) MEDIUM
- Shoplentor - Cross-Site Scripting (XSS) (CVE-2024-2868) MEDIUM
- Shoplentor - PHP Object Injection (CVE-2023-0232) CRITICAL
- Shoplentor - Cross-Site Scripting (XSS) (CVE-2023-0231) MEDIUM