PT-2026-20284 · Unknown+3 · Woocommerce+3

Teerachai Somprasong

·

Publicado

2026-02-18

·

Atualizado

2026-02-23

·

CVE-2026-1714

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress versions prior to 3.3.3
Description The ShopLentor plugin is susceptible to Email Relay Abuse due to insufficient validation of input parameters. Specifically, the send to, product title, wlmessage, and wlemail parameters within the woolentor suggest price action API endpoint are not properly validated. This allows unauthenticated attackers to leverage the website as an email relay for malicious purposes, such as spam or phishing campaigns. Attackers gain full control over the email subject line, message content, and sender address through CRLF injection within the wlemail parameter.
Recommendations Versions prior to 3.3.3 should be updated to version 3.3.3 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1714

Produtos afetados

Elementor
Gutenberg
Shoplentor
Woocommerce