The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to view all products purchased in the past week, along with the users that purchased them.
References
Configurations
History
25 Nov 2025, 19:51
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Hasthemes
Hasthemes shoplentor |
|
| CWE | CWE-862 | |
| CPE | cpe:2.3:a:hasthemes:shoplentor:*:*:*:*:*:wordpress:*:* | |
| References | () https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/2.7.4/includes/modules/sales-notification/class.sale_notification.php - Product | |
| References | () https://plugins.trac.wordpress.org/changeset/3080097/woolentor-addons/trunk/includes/modules/sales-notification/class.sale_notification.php?contextall=1&old=3061864&old_path=%2Fwoolentor-addons%2Ftrunk%2Fincludes%2Fmodules%2Fsales-notification%2Fclass.sale_notification.php - Patch | |
| References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/263324cb-31b7-40ad-ad7d-4582e128cd75?source=cve - Third Party Advisory |
Information
Published : 2024-05-14 14:33
Updated : 2025-11-25 19:51
NVD link : CVE-2023-6327
Mitre link : CVE-2023-6327
CVE.ORG link : CVE-2023-6327
JSON object : View
Products Affected
hasthemes
- shoplentor
CWE
CWE-862
Missing Authorization
