Impact
The ShopLentor Pro WordPress plugin versions up to 2.8.5 contains an unauthenticated broken access control flaw. This flaw allows an attacker to invoke privileged administrative functions without authenticating, because the plugin does not enforce proper authorization checks when handling certain requests. With this vulnerability, a malicious user could alter shop configurations, manipulate product data, or inject malicious content into the e‑commerce storefront. The weakness is categorized as CWE‑862, indicating missing authorization checks.
Affected Systems
The vulnerability affects installations that have the WooLentor ShopLentor Pro plugin version 2.8.5 or earlier. These plugins are typically deployed in WordPress e‑commerce sites to provide advanced shop features. Only this product and vendor are listed as impacted; no other WordPress plugins or platforms are affected according to the CNA data.
Risk and Exploitability
A CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1 % signals a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is remote, unauthenticated via the public HTTP interface to the plugin’s administrative endpoints. This inference is based on the description of unauthenticated access control; the exact vector is not explicitly stated in the CVE data.
OpenCVE Enrichment