Stored Cross-Site Scripting in ShopLentor Plugin for WordPress
CVE-2026-4059
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-4059?
The ShopLentor plugin for WordPress is susceptible to Stored Cross-Site Scripting due to a lack of proper input sanitization and output escaping on the 'button_text' attribute of the 'woolentor_quickview_button' shortcode. Authenticated users with Contributor-level access or higher can exploit this vulnerability to inject arbitrary JavaScript code into web pages. This could lead to harmful scripts executing whenever users access the compromised pages, potentially compromising user data and site integrity.
Affected Version(s)
ShopLentor β All-in-One WooCommerce Growth & Store Enhancement Plugin 0 <= 3.3.5