MEDIUM
ShopLentor <= 2.9.8 - Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template
Published Oct 11, 2024
6.5
MEDIUMCVSS 3.1
EPSS 0.40%
Description
The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.8 via the 'render' function in includes/addons/wl_faq.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft Elementor template data.
Affected products
- Vendor Devitemsllc Product ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin Defaultunaffected
- Version 0StatusaffectedConstraints<=2.9.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Devitemsllc | ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin | unaffected |
|
- < 2.9.9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49997 Advisory
- https://plugins.trac.wordpress.org/changeset/3164057/woolentor-addons Product
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6b36938e-5333-4331-9bb1-34465fe03f2f?source=cve Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49997 | Advisory | |
| https://plugins.trac.wordpress.org/changeset/3164057/woolentor-addons | Product | |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/6b36938e-5333-4331-9bb1-34465fe03f2f?source=cve | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Oct 11, 2024
Updated Apr 8, 2026
Reserved Oct 4, 2024
Link CVE-2024-9538
CISA Vulnrichment
Updated Oct 11, 2024
ENISA EUVD
EUVD-2024-49997 Assigner Wordfence
Published Oct 11, 2024
Updated Apr 8, 2026
Exploited since n/a
Link EUVD-2024-49997