Description
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
Published: 2026-07-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ShopLentor Pro WordPress plugin versions up to 2.8.5 contains an unauthenticated broken access control flaw. This flaw allows an attacker to invoke privileged administrative functions without authenticating, because the plugin does not enforce proper authorization checks when handling certain requests. With this vulnerability, a malicious user could alter shop configurations, manipulate product data, or inject malicious content into the e‑commerce storefront. The weakness is categorized as CWE‑862, indicating missing authorization checks.

Affected Systems

The vulnerability affects installations that have the WooLentor ShopLentor Pro plugin version 2.8.5 or earlier. These plugins are typically deployed in WordPress e‑commerce sites to provide advanced shop features. Only this product and vendor are listed as impacted; no other WordPress plugins or platforms are affected according to the CNA data.

Risk and Exploitability

A CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1 % signals a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is remote, unauthenticated via the public HTTP interface to the plugin’s administrative endpoints. This inference is based on the description of unauthenticated access control; the exact vector is not explicitly stated in the CVE data.

Generated by OpenCVE AI on August 3, 2026 at 22:14 UTC.

Remediation

Vendor Solution

Update the WordPress ShopLentor Pro Plugin to the latest available version (at least 2.8.6).


OpenCVE Recommended Actions

  • Upgrade the ShopLentor Pro plugin to version 2.8.6 or later, which removes the broken access control flaw.
  • If an update is not immediately possible, restrict network access to the plugin’s administrative URLs using a firewall or web application firewall and block them from all but trusted IP addresses.
  • Apply least‑privilege role assignments for users who can access the plugin and enable two‑factor authentication for administrative accounts to reduce the impact of potential unauthorized access.

Generated by OpenCVE AI on August 3, 2026 at 22:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Woolentor
Woolentor shoplentor Pro
Wordpress
Wordpress wordpress
Vendors & Products Woolentor
Woolentor shoplentor Pro
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
Title WordPress ShopLentor Pro plugin <= 2.8.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Woolentor Shoplentor Pro
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T14:46:17.148Z

Reserved: 2026-07-13T06:13:50.885Z

Link: CVE-2026-61972

cve-icon Vulnrichment

Updated: 2026-07-23T14:46:13.884Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:35.163

Modified: 2026-07-23T15:17:41.763

Link: CVE-2026-61972

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:15:04Z

Weaknesses