Junglewise Threat Intelligence

CVE-2026-27330: Mobile App for WooCommerce broken access control vulnerability

CVE-2026-27330 · Severity: high · CVSS 8.6 · Published 2026-08-27

Technologies: ShopApper Mobile App for WooCommerce. Vendors: ShopApper.

Executive brief

The Mobile App for WooCommerce plugin allows unauthenticated attackers to bypass access controls and view or manipulate data they should not have permission to access. This affects WordPress-based online stores using the plugin, potentially exposing customer data, order information, and enabling unauthorized modifications to shop functionality without requiring any login credentials.

Technical details

A broken access control vulnerability exists in the Mobile App for WooCommerce plugin versions up to and including 0.4.62, allowing unauthenticated users to access restricted pages and perform actions normally reserved for authenticated users. The vulnerability requires no authentication and is network-accessible, making it trivial to exploit at scale. Attackers can view sensitive customer and order data, and potentially perform unauthorized administrative actions. The vulnerability was patched in version 0.4.63, and users are strongly advised to update immediately.

Affected products

  • ShopApper Mobile App for WooCommerce ≤0.4.62

Timeline

  • 2026-08-25: disclosed: Vulnerability published by Patchstack
  • 2026-08-25: patched: Fix released in version 0.4.63

References

Related threats