The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.5 via the 'optionSection' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to read arbitrary wp_options rows — including internal plugin news feed data, WooCommerce block pattern transients, and third-party configuration records — whose values are stored as arrays-of-arrays containing 'title' keys, enabling cross-plugin data leakage.
We have discovered 10,998 live websites that are affected by CVE-2026-16797.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 10,998 live websites (100% of Woolentor Addons install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 162 versions ( 100% of all versions) |
| 2,746 websites | |
| 706 websites | |
| 695 websites | |
| 561 websites | |
| 403 websites | |
| 378 websites | |
| 368 websites | |
| 358 websites | |
| 326 websites | |
| 311 websites |
| .com | 5,114 websites |
| .com.br | 352 websites |
| .co.uk | 326 websites |
| .fr | 290 websites |
| .it | 251 websites |
| .de | 247 websites |
| .nl | 225 websites |
| .com.au | 219 websites |
| .ru | 208 websites |
| .pl | 205 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.**.il | **,*** | ||
| ************.com | **,*** | ||
| ******.ca | **,*** | ||
| ********.com | ***,*** | ||
| ******.com | ***,*** | ||
| *******.com | ***,*** | ||
| **************.it | ***,*** | ||
| *********.com | ***,*** | ||
| ******.ca | ***,*** | ||
| ***********.eu | ***,*** |
FAQ