CVE-2025-12493PoC(hasthemes / shoplentor)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the 'load_template' function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • shoplentor

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-25); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
shoplentor

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-25: 2Mentions · 2026-02-26: 1PoC Mentioned / Linked · 2026-02-25: 2Technical Details · 2026-02-25: 2Technical Details · 2026-02-26: 102-2502-26
Signal classification2 categories
PoC
266.7%
Disclosure
133.3%
Classification over time
DateTotalLabels
2026-02-252
PoC2
2026-02-261
Disclosure1
Full discourse3 posts
  • norahc@viii_norahc
    PoC

    ‼️#POC CVE-2025-12493: ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion CVSS: 9.8 Software Downloads: 5.169.996 Software Active Installs: 90.000 POC: 👇👇👇 #CVE #bugbountytip #wordpress #exploit #bugbounty #bugbountytips #bugbountytip

    Post summary

    A PoC for CVE-2025-12493 is announced, highlighting an unauthenticated local PHP file inclusion vulnerability with a high CVSS score, but no exploit code or patch details are provided.

    20100189
    3 followersView on X
  • norahc@viii_norahc
    Disclosure

    🚨 Bug Bounty Tips & Tricks: CVE-2025-12493 From LFI to Full WordPress Compromise 🚨 How a simple unauthenticated LFI in a popular plugin turned into high-impact access 🧵 🔎 1. The Recon: Always test AJAX / dynamic template loading features in Elementor addons. Found that ShopLentor ≤ 3.2.5 was loading local files based on user input → no authentication, no proper sanitization. 🧨 2. The Exploit: Used path traversal payloads to read arbitrary local PHP files. Accessed sensitive files: wp-config.php → database credentials plugin internal files → application logic No login required. 💥 3. The Impact: ✅ Database access → dump users & password hashes ✅ Authentication material disclosure ✅ Full site compromise path #bugbountytip #bugbountytips #infosec #recon

    Post summary

    The post discloses an unauthenticated LFI in ShopLentor ≤3.2.5, detailing how path traversal can read sensitive files such as wp-config.php, enabling full site compromise.

    0000076
    3 followersView on X
  • norahc@viii_norahc
    PoC

    #POC CVE-2025-12493: ShopLentor &lt;= 3.2.5 - Unauthenticated LFI PHP https://t.co/6ApvgA2RJu

    Post summary

    A proof‑of‑concept for CVE-2025-12493, an unauthenticated local file inclusion vulnerability in ShopLentor versions up to 3.2.5, is shared via a link.

    0000079
    3 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphasthemesshoplentor-wordpress-

Explore more