Email Relay Abuse in ShopLentor β WooCommerce Builder for Elementor
CVE-2026-1714
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 February 2026
What is CVE-2026-1714?
The ShopLentor β WooCommerce Builder for Elementor & Gutenberg +21 Modules plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit a lack of validation on parameters in the 'woolentor_suggest_price_action' AJAX endpoint. Due to this flaw, attackers can send arbitrary emails to any recipient, gaining full control over the content, subject line, and sender address through CRLF injection in the 'wlemail' parameter. This vulnerability effectively transforms the website into a tool for conducting spam or phishing campaigns, raising significant security concerns for WordPress users and their audiences.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ShopLentor β All-in-One WooCommerce Growth & Store Enhancement Plugin * <= 3.3.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved