🔐 CVE Alert

CVE-2026-1714

HIGH 8.6

ShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action

CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abuse in all versions up to, and including, 3.3.2. This is due to the lack of validation on the 'send_to', 'product_title', 'wlmessage', and 'wlemail' parameters in the 'woolentor_suggest_price_action' AJAX endpoint. This makes it possible for unauthenticated attackers to send arbitrary emails to any recipient with full control over the subject line, message content, and sender address (via CRLF injection in the 'wlemail' parameter), effectively turning the website into a full email relay for spam or phishing campaigns.

CWE CWE-93
Vendor devitemsllc
Product shoplentor – all-in-one woocommerce growth & store enhancement plugin
Published Feb 18, 2026
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for devitemsllc shoplentor – all-in-one woocommerce growth & store enhancement plugin

Be the first to know when new high vulnerabilities affecting devitemsllc shoplentor – all-in-one woocommerce growth & store enhancement plugin are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

devitemsllc / ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
0 ≤ 3.3.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/cf326914-6a38-4984-a2a7-66e05f41a96b?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/woolentor-addons/trunk/classes/class.ajax_actions.php#L170 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/3.3.1/classes/class.ajax_actions.php#L170 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/woolentor-addons/trunk/classes/class.ajax_actions.php#L189 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/3.3.1/classes/class.ajax_actions.php#L189 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/woolentor-addons/trunk/classes/class.ajax_actions.php#L192 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/3.3.1/classes/class.ajax_actions.php#L192 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3461704/woolentor-addons/trunk/classes/class.ajax_actions.php?contextall=1

Credits

Teerachai Somprasong