What is CVE-2026-16811?
The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin for WordPress, up to version 3.4.5, is vulnerable to time-based SQL Injection via the 'orderby' parameter. This is caused by insufficient escaping of user input and lack of prepared statements. Immediate update to the latest patched version is strongly recommended.
Azərbaycanca: ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin-in 3.4.5-dək bütün versiyalarında 'orderby' parametri vasitəsilə time-based SQL Injection zəifliyi aşkar edilib. Bu, istifadəçi tərəfindən təqdim olunan məlumatın düzgün escapelənməməsi və hazırlanmış sorğulardan istifadə edilməməsi səbəbindən baş verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the ShopLentor plugin are affected by CVE-2026-16811 SQL Injection vulnerability?
All versions of the ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin up to 3.4.5 are affected by this time-based SQL Injection vulnerability.
What is the root cause of the CVE-2026-16811 vulnerability?
The vulnerability exists because of insufficient escaping of user input and the lack of prepared statements via the 'orderby' parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.