Description
The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to view all products purchased in the past week, along with the users that purchased them.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58569 | The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to view all products purchased in the past week, along with the users that purchased them. |
References
History
Tue, 25 Nov 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hasthemes
Hasthemes shoplentor |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:hasthemes:shoplentor:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Hasthemes
Hasthemes shoplentor |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-02T08:28:21.809Z
Reserved: 2023-11-27T15:12:20.350Z
Link: CVE-2023-6327
Updated: 2024-08-02T08:28:21.809Z
Status : Analyzed
Published: 2024-05-14T14:33:18.653
Modified: 2025-11-25T19:51:27.447
Link: CVE-2023-6327
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:21:39Z
Weaknesses
EUVD