Junglewise Threat Intelligence

CVE-2026-6287: ShopLentor WordPress plugin stored XSS in Product Grid blocks

CVE-2026-6287 · Severity: medium · CVSS 5.4 · Published 2026-05-27

Vendors: HasThemes.

Executive brief

ShopLentor is a popular WordPress plugin used to build and customize WooCommerce online stores. A security flaw in this plugin allows users with low-level account access, such as contributors, to embed malicious scripts into store pages. When other users or administrators visit these pages, the scripts can execute, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

The ShopLentor plugin for WordPress (versions up to 3.3.8) is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'blockUniqId' attribute within various Product Grid blocks. An authenticated attacker with contributor-level permissions or higher can inject arbitrary web scripts into a page. These scripts execute in the context of a user's browser whenever they visit the affected page. The vulnerability is tracked as CWE-79 and was addressed in a subsequent changeset.

Affected products

  • HasThemes ShopLentor – WooCommerce Builder for Elementor & Gutenberg Up to and including 3.3.8

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References