๐Ÿ” CVE Alert

CVE-2026-47745

MEDIUM 6.5

Shopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admin tables

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, disable, edit, delete) that were rendered for any authenticated panel user without checking the corresponding per-action permission. A low-privilege user could disable every payment method on the store, disable or alter the default currency, or disable carriers. The impact is a full denial of checkout and pricing integrity loss, reachable by any authenticated user. This vulnerability is fixed in 2.8.0.

CWE CWE-862
Vendor shopperlabs
Product shopper
Published May 29, 2026
Last Updated May 29, 2026
Stay Ahead of the Next One

Get instant alerts for shopperlabs shopper

Be the first to know when new medium vulnerabilities affecting shopperlabs shopper are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

shopperlabs / shopper
< 2.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/shopperlabs/shopper/security/advisories/GHSA-fxqw-97cc-7g5c github.com: https://github.com/shopperlabs/shopper/pull/511