WordPress Plugin Vulnerabilities

ShopLentor < 3.3.8 - Admin+ Arbitrary Function Execution via 'callback' Parameter via REST API

Description

The plugin is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint due to the handle_action() method passing user-supplied input directly to call_user_func() without an allowlist of permitted callbacks. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP callable functions via the 'callback' parameter.

Affects Plugins

Fixed in 3.3.8

References

Classification

Type
RCE
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
Itthidej Aramsri (Boeing777), Waris Damkham, Teerachai Somprasong
Verified
No

Timeline

Publicly Published
2026-08-04 (about 20 days ago)
Added
2026-08-04 (about 19 days ago)
Last Updated
2026-08-04 (about 19 days ago)

Other