CVE 8.6 HIGH

ShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action_CVE-2026-1714

8.6 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Description

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abuse in all versions up to, and including, 3.3.2. This is due to the lack of validation on the 'send_to', 'product_title', 'wlmessage', and 'wlemail' parameters in the 'woolentor_suggest_price_action' AJAX endpoint. This makes it possible for unauthenticated attackers to send arbitrary emails to any recipient with full control over the subject line, message content, and sender address (via CRLF injection in the 'wlemail' parameter), effectively turning the website into a full email relay for spam or phishing campaigns.

AI Analysis

Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action

Basic Information

ID CVE-2026-1714
Source Wordfence
Published Feb 18, 2026 at 04:35

Affected Product

Vendor devitemsllc
Product ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
Version *
Affected Versions devitemsllc ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin *

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor devitemsllc
Product ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
Version 3.3.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.