PT-2025-44993 · Automattic+2 · Woocommerce+3

Michael Mazzolini

·

Published

2025-11-04

·

Updated

2026-02-26

·

CVE-2025-12493

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ShopLentor versions prior to 3.2.6
Description The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is susceptible to Local File Inclusion in versions up to and including 3.2.5. This allows unauthenticated attackers to include and execute arbitrary .php files on the server through the load template function. Successful exploitation could lead to bypassing access controls, obtaining sensitive data, or achieving code execution if .php file uploads are permitted.
Recommendations Update ShopLentor to version 3.2.6 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-12493

Affected Products

Elementor
Gutenberg
Shoplentor
Woocommerce