CVE-2026-16797
Received Received - Intake

Insecure Direct Object Reference in ShopLentor WooCommerce Plugin

Vulnerability report for CVE-2026-16797, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: Wordfence

Description

The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.5 via the 'optionSection' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to read arbitrary wp_options rows β€” including internal plugin news feed data, WooCommerce block pattern transients, and third-party configuration records β€” whose values are stored as arrays-of-arrays containing 'title' keys, enabling cross-plugin data leakage.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-28
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
shoplentor all-in-one_woocommerce_growth_&_store_enhancement_plugin to 3.4.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) in the ShopLentor WordPress plugin. It allows authenticated attackers with contributor-level access or higher to read arbitrary wp_options rows by manipulating the 'optionSection' parameter. The issue occurs due to missing validation on a user-controlled key, enabling access to sensitive data like plugin news feeds, WooCommerce transients, and third-party configurations stored as arrays.

Detection Guidance

To detect this vulnerability, inspect WordPress sites using the ShopLentor plugin versions up to 3.4.5. Check for unauthorized access to wp_options via the 'optionSection' parameter. Review server logs for suspicious queries targeting plugin-specific options or transients.

Impact Analysis

If you use the ShopLentor plugin, attackers could exploit this to access internal plugin data, WooCommerce settings, or other third-party configurations. This may lead to data leaks, unauthorized access to sensitive information, or potential manipulation of store settings if combined with other vulnerabilities.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA compliance. Exposure of user data or configurations may result in regulatory fines, legal liabilities, and reputational damage due to non-compliance with data protection requirements.

Mitigation Strategies

Immediately update the ShopLentor plugin to the latest version beyond 3.4.5. If an update is unavailable, consider disabling the plugin temporarily. Restrict contributor-level and higher user roles to prevent unauthorized access. Monitor wp_options for unusual modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16797. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart