QSearchQSearch

CVE-2026-47742

6.5 MEDIUM

Shopper is a Headless e-commerce Admin Panel

Published: 2026-05-29 · Last updated: 2026-05-29

Severity and scoring

CVSS
6.5 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE
CWE-862

Description

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no authorization on their store() method. Any authenticated panel user, regardless of role, could mutate any product's pricing, stock, SEO metadata, shipping dimensions, and attached media without holding edit_products. The affected components accepted the product ID as a public Livewire property without #[Locked], so an attacker could also target an arbitrary product by tampering with the wire payload from the client. This vulnerability is fixed in 2.8.0.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-6964 The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7 (5.3 MEDIUM)
  • CVE-2026-49775 Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions (6.5 MEDIUM)
  • CVE-2026-49070 Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions (7.5 HIGH)
  • CVE-2026-49065 Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions (8.2 HIGH)
  • CVE-2026-48887 Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions (6.5 MEDIUM)