Executive brief
ShopLentor Pro, a popular WordPress plugin used for building WooCommerce online stores, contains a security flaw that allows users with low-level 'Subscriber' accounts to perform unauthorized actions. This could allow an attacker to modify certain site settings or data that should normally be restricted to administrators. While the impact is limited to data integrity rather than full site takeover, it poses a risk to the operational consistency of the online store.
Technical details
A broken access control vulnerability exists in ShopLentor Pro versions up to and including 2.8.5 due to missing authorization checks (CWE-862). An authenticated attacker with Subscriber-level privileges can exploit this flaw over the network to perform unauthorized modifications to site data or settings. The vulnerability is rated with a CVSS score of 4.3, indicating a low impact on integrity with no impact on confidentiality or availability. Users are advised to upgrade to version 2.8.6 or later to remediate the issue.
Affected products
- WooLentor ShopLentor Pro <= 2.8.5
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory