Authorization Flaw in Shopper Headless E-commerce Admin Panel
CVE-2026-47742

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-47742?

A significant flaw was detected in the Shopper Headless e-commerce Admin Panel prior to version 2.8.0. The issue resides in the Sub-form Livewire components used within the product editor, such as those for managing inventory, SEO, shipping, and attached media. These components lack proper authorization on their store() method, enabling any authenticated user to alter the pricing, stock levels, SEO metadata, shipping dimensions, and media associated with any product. The vulnerability arises from the public exposure of the product ID as a Livewire property, allowing potential attackers to exploit this flaw by manipulating the wire payload. This serious issue has been resolved in version 2.8.0, underscoring the importance of timely software updates.

Affected Version(s)

shopper < 2.8.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.