Executive brief
ShopLentor is a popular WordPress plugin used to enhance WooCommerce online stores with features like abandoned cart recovery. A security vulnerability in this plugin allows an attacker with administrative access to perform unauthorized database queries. This could lead to the theft of sensitive store information, including customer data or site configuration details.
Technical details
The ShopLentor plugin for WordPress is vulnerable to a time-based SQL Injection vulnerability within the 'orderby' parameter. The flaw exists in the Abandoned Cart module due to insufficient escaping of user-supplied input and a lack of proper SQL query preparation in the DB_Handler.php and Cart_Data.php components. An authenticated attacker with administrator-level privileges can exploit this to append additional SQL queries, enabling the extraction of sensitive data from the WordPress database. The issue is addressed in versions following 3.4.5.
Affected products
- devitemsllc ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin up to, and including, 3.4.5
Timeline
- 2026-07-28: advisory: Published by Wordfence and NVD
References
- https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/3.4.5/includes/modules/abandoned-cart/includes/classes/Api/Cart_Data.php
- https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/3.4.5/includes/modules/abandoned-cart/includes/classes/Database/DB_Handler.php
- https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/3.4.5/includes/modules/abandoned-cart/includes/classes/Database/DB_Handler.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3623166%40woolentor-addons&new=3623166%40woolentor-addons
- https://www.wordfence.com/threat-intel/vulnerabilities/id/bed2ada9-af3d-479e-8ae4-11eaad0b3842?source=cve