MEDIUM
devitemsllc
CVE published 2026-05-27
CVE-2026-6287
A stored cross-site scripting (XSS) vulnerability in the ShopLentor - WooCommerce Builder for Elementor & Gutenberg WordPress plugin allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts via the 'blockUniqId' block attribute in multiple Product Grid blocks. The vulnerability exists in versions up to and including 3.3.8 due to insufficient input sanitization [truncated]