Authorization Flaw in Shopper Headless E-commerce Admin Panel
CVE-2026-47742
What is CVE-2026-47742?
A significant flaw was detected in the Shopper Headless e-commerce Admin Panel prior to version 2.8.0. The issue resides in the Sub-form Livewire components used within the product editor, such as those for managing inventory, SEO, shipping, and attached media. These components lack proper authorization on their store() method, enabling any authenticated user to alter the pricing, stock levels, SEO metadata, shipping dimensions, and media associated with any product. The vulnerability arises from the public exposure of the product ID as a Livewire property, allowing potential attackers to exploit this flaw by manipulating the wire payload. This serious issue has been resolved in version 2.8.0, underscoring the importance of timely software updates.
Affected Version(s)
shopper < 2.8.0
