A vulnerability was found in devitems ShopLentor Plugin up to 3.4.5 on WordPress. It has been declared as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument orderby results in sql injection.

This vulnerability is reported as CVE-2026-16811. The attack can be launched remotely. No exploit exists.