Product Manipulation Vulnerability in Shopper E-commerce Admin Panel
CVE-2026-56830
6.5MEDIUM
What is CVE-2026-56830?
A vulnerability in the Shopper E-commerce Admin Panel allows authenticated staff users with browsing permissions to bypass authorization checks when replacing product images. Specifically, prior to version 2.9.2, the store() function in the Media component lacked the necessary edit_products authorization, permitting unauthorized changes to product thumbnails and galleries. This issue affects only those products whose edit pages have been previously accessed, limiting the potential for broader exploitation. The vulnerability has been addressed in the latest update, version 2.9.2.
Affected Version(s)
shopper < 2.9.2
