The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to view all products purchased in the past week, along with the users that purchased them.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: Wordfence
Published: 2024-05-09T20:03:21.876Z
Updated: 2024-08-02T08:28:21.809Z
Reserved: 2023-11-27T15:12:20.350Z
Link: CVE-2023-6327

Updated: 2024-08-02T08:28:21.809Z

Status : Awaiting Analysis
Published: 2024-05-14T14:33:18.653
Modified: 2024-11-21T08:43:38.007
Link: CVE-2023-6327

No data.