PatchSiren

devitemsllc CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH devitemsllc CVE published 2026-08-05

CVE-2026-6020

The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint in all versions up to, and including, 3.3.7. This is due to the handle_action() method passing user-supplied input directly to call_user_func() without an allowlist of permitted callbacks. This makes it possible for authenticated attackers, with Administrator-level acce [truncated]

MEDIUM devitemsllc CVE published 2026-07-08

CVE-2026-12936

The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 1.1.3. This vulnerability is due to insufficient escaping on the user-supplied parameter and a lack of sufficient preparation on the existing SQL query. Authenticated attackers with shop manager-level access and above can inject SQL [truncated]

MEDIUM devitemsllc CVE published 2026-05-27

CVE-2026-6287

A stored cross-site scripting (XSS) vulnerability in the ShopLentor - WooCommerce Builder for Elementor & Gutenberg WordPress plugin allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts via the 'blockUniqId' block attribute in multiple Product Grid blocks. The vulnerability exists in versions up to and including 3.3.8 due to insufficient input sanitization [truncated]