cleantalk
Vulnerabilities and Security Researches

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor), CVE-2023-0232

CVE, Research URL

CVE-2023-0232

Published on
Feb 21, 2023
Research Description
The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.
Affected versions
Min -, max 2.5.4.
Status
vulnerable