PatchSiren

devitemsllc CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM devitemsllc CVE published 2026-05-27

CVE-2026-6287

A stored cross-site scripting (XSS) vulnerability in the ShopLentor - WooCommerce Builder for Elementor & Gutenberg WordPress plugin allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts via the 'blockUniqId' block attribute in multiple Product Grid blocks. The vulnerability exists in versions up to and including 3.3.8 due to insufficient input sanitization [truncated]