Impact
The ShopLentor – All‑in‑One WooCommerce Growth & Store Enhancement Plugin has a reflected cross‑site scripting flaw that enables an unauthenticated attacker to inject arbitrary JavaScript into pages by supplying a crafted query‑string parameter name. Because the plugin copies the parameter name directly into an HTML value attribute without sanitization or escaping, the payload can escape that attribute and execute when a user visits the URL.
Affected Systems
WordPress sites that use the ShopLentor plugin version 3.5.1 or earlier. The vulnerability is present in the WL: Product Horizontal Filter widget, which displays anything supplied in the query‑string parameter name in an option element. All vendors identified by the CNA indicate that the plugin is affected through all releases up to 3.5.1.
Risk and Exploitability
The flaw has a CVSS score of 6.1 and an EPSS score of less than 1 %, indicating a moderate severity and a low probability of exploitation in the wild. It is not listed in the CISA Known Exploited Vulnerabilities catalog. Because an attacker only needs to entice an end‑user to click a malicious link containing the crafted parameter name, the risk is limited to victims who view the vulnerable plugin’s output. Successful exploitation could lead to defacement, phishing, or the delivery of additional payloads in the affected user's browser, but does not provide server‑side code execution.
OpenCVE Enrichment