Reflected Cross-Site Scripting in ShopLentor Plugin for WordPress
CVE-2026-92554

6.1MEDIUM

What is CVE-2026-92554?

The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit reflected cross-site scripting (XSS). This occurs when an attacker supplies malicious query-string parameter names. The WL: Product Horizontal Filter widget reflects these names into option element value attributes without appropriate input sanitization and output escaping, enabling the execution of arbitrary web scripts. Users can be manipulated into triggering the vulnerability by clicking on specially crafted links, posing a significant risk to their security.

Affected Version(s)

ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin 0 <= 3.5.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kuba
.