Local File Inclusion Vulnerability in ShopLentor Plugin for WordPress
CVE-2025-12493
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 November 2025
What is CVE-2025-12493?
The ShopLentor plugin for WordPress is susceptible to a local file inclusion vulnerability that affects all versions up to and including 3.2.5. The flaw lies in the 'load_template' function, which allows unauthenticated users to include and execute arbitrary PHP files from the server. This vulnerability can pave the way for attackers to bypass access controls, access sensitive information, and even execute PHP code if they manage to upload .php files. As such, it poses significant risks to WordPress installations utilizing this plugin.
Affected Version(s)
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) * <= 3.2.5