The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.
2023-02-21T09:15:12.107
2025-03-12T21:15:40.023
Modified
CVSSv3.1: 9.8 (CRITICAL)
-
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | hasthemes | shoplentor | < 2.5.4 | Yes |