Vulnerability in Headless E-commerce Admin Panel by Shopper Exposes Permissions to Authenticated Users
CVE-2026-47745
6.5MEDIUM
What is CVE-2026-47745?
In versions prior to 2.8.0 of Shopper's Headless e-commerce Admin Panel, there is a significant security flaw whereby inline toggles and actions related to PaymentMethods, Currencies, and Carriers were accessible to any authenticated user without appropriate permission checks. This weakness allows low-privilege users to disable vital components like payment methods and the default currency, which can lead to severe operational disruptions and affect pricing integrity. The vulnerability was addressed in version 2.8.0, enhancing the security architecture to prevent such unauthorized actions.
Affected Version(s)
shopper < 2.8.0
