Impact
The vulnerability permits an attacker with Contributor or higher privileges to store malicious JavaScript through the button_text attribute of the woolentor_quickview_button shortcode. Because this attribute is neither sanitized nor escaped, the injected script remains in the database and is executed whenever any visitor loads a page containing the shortcode. Attackers can thereby steal cookies, hijack sessions, deface content, or disclose sensitive data to a prompted or background script, representing a classic web scripting weakness.
Affected Systems
All releases of the ShopLentor All‑in‑One WooCommerce Growth & Store Enhancement Plugin from DevItems LLC up to and including version 3.3.5 are affected. The flaw is fixed in version 3.3.6 and later.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and the lack of an EPSS rating means the exact exploitation probability is unknown; however, the requirement for only Contributor‑level authentication makes the attack path reasonable in typical hosting scenarios. The vulnerability is not listed in the CISA KEV catalog, so no large‑scale active exploitation has been documented, but stored XSS is a well‑known vector for widespread damage once deployed.
OpenCVE Enrichment