The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to view all products purchased in the past week, along with the users that purchased them.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Nov 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hasthemes
Hasthemes shoplentor |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:hasthemes:shoplentor:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Hasthemes
Hasthemes shoplentor |
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-05-09T20:03:21.876Z
Updated: 2024-08-02T08:28:21.809Z
Reserved: 2023-11-27T15:12:20.350Z
Link: CVE-2023-6327
Updated: 2024-08-02T08:28:21.809Z
Status : Analyzed
Published: 2024-05-14T14:33:18.653
Modified: 2025-11-25T19:51:27.447
Link: CVE-2023-6327
No data.