{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/shoplentor-3.3.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-6020"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ShopLentor (3.3.7)"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","cve-2026-6020","rce"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe ShopLentor plugin for WordPress, specifically in versions 3.3.7 and earlier, contains a critical security flaw identified as CVE-2026-6020. The vulnerability resides in the \u003ccode\u003ewoolentoropt/v1/custom-action\u003c/code\u003e REST API endpoint. The underlying \u003ccode\u003ehandle_action()\u003c/code\u003e method fails to validate user-supplied input, directly passing the \u003ccode\u003ecallback\u003c/code\u003e parameter to the PHP \u003ccode\u003ecall_user_func()\u003c/code\u003e function without an allowlist.\u003c/p\u003e\n\u003cp\u003eThis vulnerability allows an attacker who has already obtained Administrator-level privileges on a WordPress site to execute arbitrary PHP functions on the underlying web server. By providing a malicious callback value, an authenticated attacker can achieve remote code execution, which could lead to full site compromise, exfiltration of database contents, or lateral movement within the hosting environment. Defenders should focus on auditing REST API requests for calls to this endpoint that involve sensitive PHP functions or unexpected payloads.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated administrator to execute arbitrary code on the server hosting the WordPress instance. This risk level is high given that it grants an attacker complete control over the application environment. Victims are limited to WordPress instances running the vulnerable ShopLentor plugin (version 3.3.7 or lower), representing a targeted set of e-commerce installations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the ShopLentor plugin to the latest version immediately to patch CVE-2026-6020.\u003c/li\u003e\n\u003cli\u003eAudit administrative access logs for the site to identify unauthorized or suspicious user account activity.\u003c/li\u003e\n\u003cli\u003eImplement the Sigma rule below to monitor for abuse of the vulnerable API endpoint within web server access logs.\u003c/li\u003e\n\u003cli\u003eRestrict access to the WordPress \u003ccode\u003e/wp-json/\u003c/code\u003e REST API namespace for non-essential administrative accounts if possible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T09:16:07Z","date_published":"2026-08-05T09:16:07Z","id":"https://feed.craftedsignal.io/briefs/2026-08-shoplentor-rce/","summary":"The ShopLentor WordPress plugin is vulnerable to authenticated remote code execution via insecure deserialization of user input in the REST API handler, allowing administrators to execute arbitrary PHP functions.","title":"CVE-2026-6020 Arbitrary Function Execution in ShopLentor Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-shoplentor-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - ShopLentor (3.3.7)","version":"https://jsonfeed.org/version/1.1"}