PT-2026-44945 · Shopper · Shopper

·

CVE-2026-47745

·

Published

2026-05-29

·

Updated

2026-07-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Shopper versions prior to 2.8.0
Description In the admin tables for PaymentMethods, Currencies, and Carriers, inline toggles and per-record actions such as enable, disable, edit, and delete are rendered for any authenticated panel user without verifying the required per-action permissions. This allows a low-privilege user to disable all payment methods, alter or disable the default currency, or disable carriers, resulting in a complete denial of the checkout process and loss of pricing integrity.
Recommendations Update to version 2.8.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47745
GHSA-FXQW-97CC-7G5C

Affected Products

Shopper