Authorization Flaw in Shopper E-commerce Admin Panel Affects Bulk Actions
CVE-2026-56827
8.1HIGH
What is CVE-2026-56827?
The Shopper E-commerce Admin Panel has an authorization flaw in multiple Livewire pages prior to version 2.9.2, which allows browse-only staff users to perform bulk deletion of attributes or tags without proper authorization. This issue can potentially disrupt storefront catalog visibility by altering the visibility settings of attributes, brands, categories, and suppliers. Notably, individual record actions and authorization of comparison pages remain unaffected. Users are encouraged to update to the fixed version 2.9.2 to mitigate these risks.
Affected Version(s)
shopper < 2.9.2
