PT-2026-47190 · Beikeshop · Beikeshop+1

·

CVE-2026-11462

·

Published

2026-06-07

·

Updated

2026-06-08

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BeikeShop versions prior to 1.6.0.22
Description Improper authorization exists in the Stripe Plugin component. A remote attacker can manipulate the Request argument within the callback() function of the file 'plugins/Stripe/Controllers/StripeController.php' to bypass authorization controls.
Recommendations Install patch 6719e0fc690ea0a998452092862e0f0a17c65968 for versions prior to 1.6.0.22. As a temporary workaround, restrict access to the callback() function in 'plugins/Stripe/Controllers/StripeController.php' to minimize the risk of exploitation.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11462

Affected Products

Beikeshop
Stripe Plugin