CVE-2026-1714Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abuse in all versions up to, and including, 3.3.2. This is due to the lack of validation on the 'send_to', 'product_title', 'wlmessage', and 'wlemail' parameters in the 'woolentor_suggest_price_action' AJAX endpoint. This makes it possible for unauthenticated attackers to send arbitrary emails to any recipient with full control over the subject line, message content, and sender address (via CRLF injection in the 'wlemail' parameter), effectively turning the website into a full email relay for spam or phishing campaigns.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-02-18: 5Technical Details · 2026-02-18: 502-18
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Full discourse5 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1714 Email Relay Abuse Vulnerability in ShopLentor WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1714

    Post summary

    The text lists CVE-2026-1714 with a brief label of an email relay abuse vulnerability in the ShopLentor WordPress plugin and provides a link to a vulnerability details page, but offers no actionable or detailed information.

    0000022
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1714: HIGH] Vulnerability Alert: ShopLentor plugin for WordPress up to version 3.3.2 susceptible to Email Relay Abuse due to lack of validation, enabling unauthenticated attacks.#cve,CVE-2026-1714,#cybersecurity https://cvefind.com/CVE-2026-1714

    Post summary

    The tweet announces a high‑severity vulnerability (CVE‑2026‑1714) in the ShopLentor WordPress plugin that permits unauthenticated email relay abuse, without mentioning active exploitation, patches, or PoCs.

    0000037
    580 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-1714 📊 Severity: 8.6 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1714 #CVE-2026-1714 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/QLEQXR4ViJ

    Post summary

    The tweet announces the new CVE-2026-1714 for WordPress, indicating a high severity score of 8.6, but provides no additional details such as PoC, exploit code, or patch.

    0000046
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1714 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abuse in all versions… https://www.cve.org/CVERecord?id=CVE-2026-1714

    Post summary

    A new CVE-2026-1714 vulnerability has been disclosed for the ShopLentor WooCommerce Builder plugin, exposing an email relay abuse flaw across all plugin versions.

    00000127
    56.4K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1714 - High The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abuse in all versions up to, and includin... https://www.thehackerwire.com/vulnerability/CVE-2026-1714/ https://t.co/cGSSj4Rb2s

    Post summary

    A high‑severity CVE-2026-1714 has been disclosed for the ShopLentor WooCommerce plugin, indicating an email relay abuse vulnerability; no PoC, exploit, or patch details are provided.

    0000045
    112 followersView on X

Explore more