Insecure Direct Object Reference in ShopLentor Plugin for WordPress
CVE-2026-16797
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-16797?
The ShopLentor β All-in-One WooCommerce Growth & Store Enhancement Plugin for WordPress suffers from a notable vulnerability due to insufficient validation on the 'optionSection' parameter. This issue allows authenticated attackers with contributor-level access or higher to exploit weak points in the system. By manipulating user-controlled keys, these attackers can access sensitive wp_options entries that include internal plugin news feed data, WooCommerce configuration records, and third-party data. This can lead to an unintentional exposure of critical information across multiple plugins, raising serious security concerns for WordPress users relying on this plugin.
Affected Version(s)
ShopLentor β All-in-One WooCommerce Growth & Store Enhancement Plugin 0 <= 3.4.5