Arbitrary Function Execution Vulnerability in ShopLentor Plugin for WordPress
CVE-2026-6020

7.2HIGH

What is CVE-2026-6020?

The ShopLentor plugin for WordPress contains a vulnerability that allows authenticated users with Administrator-level access to execute arbitrary PHP callable functions. This is due to the 'handle_action()' method directly passing user-supplied input to 'call_user_func()' without proper validation. Attackers can exploit this through the 'callback' parameter in the woolentoropt/v1/custom-action REST API endpoint, posing a serious threat to the integrity of the WordPress site.

Affected Version(s)

ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin 0 <= 3.3.7

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Itthidej Aramsri (Boeing777)
Waris Damkham
Teerachai Somprasong
.