WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

ShopLentor – More than a WooCommerce builder. A complete growth plugin to boost conversions, UX, and sales for your store.

27Reported vulnerabilities
9.8Highest CVSS score
3.4.7Latest version
80,000+Active installs

What to do now

Update ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin to 3.3.8 or later. 27 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 18, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-0232 Critical 9.8 3.3% Before 2.5.4 2.5.4 February 21, 2023
CVE-2025-12493 Critical 9.8 0.8% Before 3.2.6 3.2.6 November 4, 2025
CVE-2026-1714 High 8.6 0.6% 0 to 3.3.2 (inclusive) 3.3.3 February 18, 2026
CVE-2026-6020 High 7.2 0.5% 0 to 3.3.7 (inclusive) 3.3.8 August 5, 2026
CVE-2024-4566 High 7.1 0.4% Before 2.8.9 2.8.9 May 21, 2024
CVE-2026-4059 Medium 6.4 0.3% 0 to 3.3.5 (inclusive) 3.3.6 April 14, 2026
CVE-2025-3775 Medium 6.5 0.3% Before 3.1.3 3.1.3 April 25, 2025
CVE-2024-9538 Medium 6.5 0.4% Before 2.9.9 2.9.9 October 11, 2024
CVE-2024-34767 Medium 6.4 0.3% 2.8.7 and earlier 2.8.8 May 17, 2024
CVE-2024-2868 Medium 6.4 0.5% Before 2.8.4 2.8.4 April 4, 2024
CVE-2025-58990 Medium 6.4 0.2% 3.2.0 and earlier 3.2.1 September 9, 2025
CVE-2025-1527 Medium 5.4 0.3% Before 3.1.1 3.1.1 March 12, 2025
CVE-2024-8668 Medium 5.4 0.4% Before 2.9.8 2.9.8 September 25, 2024
CVE-2024-5530 Medium 5.4 0.4% Before 2.9.1 2.9.1 June 11, 2024
CVE-2024-3345 Medium 5.4 0.4% Before 2.8.9 2.8.9 May 21, 2024
CVE-2023-6327 Medium 5.3 0.7% Before 2.8.8 2.8.8 May 14, 2024
CVE-2024-3991 Medium 5.4 0.4% Before 2.8.8 2.8.8 May 2, 2024
CVE-2024-1057 Medium 5.4 0.3% Before 2.8.2 2.8.2 April 20, 2024
CVE-2024-1960 Medium 5.4 0.5% Before 2.8.2 2.8.2 April 9, 2024
CVE-2021-24262 Medium 5.4 0.6% Before 1.8.6 1.8.6 May 5, 2021
CVE-2026-6287 Medium 5.4 0.2% 0 to 3.3.8 (inclusive) 3.3.9 May 27, 2026
CVE-2025-11823 Medium 5.4 0.2% Before 3.2.5 3.2.5 October 25, 2025
CVE-2022-46798 Medium 5.4 0.2% 2.5.1 and earlier 2.5.2 February 6, 2023
CVE-2026-16811 Medium 4.9 0.3% 0 to 3.4.5 (inclusive) 3.4.6 July 28, 2026
CVE-2026-16797 Medium 4.3 0.2% 0 to 3.4.5 (inclusive) 3.4.6 July 28, 2026
CVE-2023-7067 Medium 4.3 0.3% Before 2.8.2 2.8.2 May 2, 2024
CVE-2022-47172 Medium 4.3 0.3% 2.6.2 and earlier 2.6.3 July 5, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.