Local File Inclusion Vulnerability in ShopLentor Plugin for WordPress
CVE-2025-12493

9.8CRITICAL

What is CVE-2025-12493?

The ShopLentor plugin for WordPress is susceptible to a local file inclusion vulnerability that affects all versions up to and including 3.2.5. The flaw lies in the 'load_template' function, which allows unauthenticated users to include and execute arbitrary PHP files from the server. This vulnerability can pave the way for attackers to bypass access controls, access sensitive information, and even execute PHP code if they manage to upload .php files. As such, it poses significant risks to WordPress installations utilizing this plugin.

Affected Version(s)

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) * <= 3.2.5

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Mazzolini
.
CVE-2025-12493 : Local File Inclusion Vulnerability in ShopLentor Plugin for WordPress