CVE-2026-6020 | devitemsllc ShopLentor Plugin up to 3.3.7 on WordPress REST API Endpoint custom-action handle_action callback code injection
A vulnerability has been found in devitemsllc ShopLentor Plugin up to 3.3.7 on WordPress and classified as problematic. This issue affects the function handle_action of the file /woolentoropt/v1/custom-action of the component REST API Endpoint. This manipulation of the argument callback causes code injection.
This vulnerability is tracked as CVE-2026-6020. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More