Arbitrary Function Execution Vulnerability in ShopLentor Plugin for WordPress
CVE-2026-6020
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-6020?
The ShopLentor plugin for WordPress contains a vulnerability that allows authenticated users with Administrator-level access to execute arbitrary PHP callable functions. This is due to the 'handle_action()' method directly passing user-supplied input to 'call_user_func()' without proper validation. Attackers can exploit this through the 'callback' parameter in the woolentoropt/v1/custom-action REST API endpoint, posing a serious threat to the integrity of the WordPress site.
Affected Version(s)
ShopLentor β All-in-One WooCommerce Growth & Store Enhancement Plugin 0 <= 3.3.7
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Itthidej Aramsri (Boeing777)
Waris Damkham
Teerachai Somprasong