Executive brief
ShopLentor Pro, a popular WooCommerce extension for WordPress, contains a security flaw that allows unauthorized users to bypass access controls. This could allow an attacker to perform actions or modify settings that should be restricted to administrators. Such an exploit could compromise the integrity of the online store's configuration or data without requiring any login credentials.
Technical details
A broken access control vulnerability exists in ShopLentor Pro (formerly WooLentor Pro) versions up to and including 2.8.5. The flaw is categorized as CWE-862 (Missing Authorization), occurring because the software fails to properly validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this over the network to perform unauthorized actions. The vulnerability is addressed in version 2.8.6.
Affected products
- WooLentor ShopLentor Pro <= 2.8.5
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory