E-commerce Admin Panel Vulnerabilities in Shopper Affecting Data Security
CVE-2026-47743
What is CVE-2026-47743?
Shopper's headless e-commerce admin panel has several vulnerabilities related to the use of Livewire components that could lead to critical security issues. These include data tampering, as authenticated users can manipulate wire payloads to access unintended records. There is also a severe risk of sensitive data disclosure due to plaintext passwords being rendered in the HTML and logged openly via Livewire snapshots. Additionally, the product barcode field is exploitable, allowing attackers with specific permissions to inject malicious payloads that could execute in the browser of any administrator. Recent updates have introduced mitigating measures such as locking vulnerable identifiers, securing password handling, and properly escaping output, yet no workarounds were available prior to version 2.8.0.
Affected Version(s)
shopper < 2.8.0
