Local File Inclusion Vulnerability in ShopLentor Plugin for WordPress
CVE-2025-12493
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 November 2025
What is CVE-2025-12493?
The ShopLentor plugin for WordPress is susceptible to a local file inclusion vulnerability that affects all versions up to and including 3.2.5. The flaw lies in the 'load_template' function, which allows unauthenticated users to include and execute arbitrary PHP files from the server. This vulnerability can pave the way for attackers to bypass access controls, access sensitive information, and even execute PHP code if they manage to upload .php files. As such, it poses significant risks to WordPress installations utilizing this plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ShopLentor β WooCommerce Builder for Elementor & Gutenberg +21 Modules β All in One Solution (formerly WooLentor) * <= 3.2.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved