Junglewise Threat Intelligence

CVE-2026-47745: Shopper Missing Authorization in Payment, Currency, and Carrier Tables

CVE-2026-47745 · Severity: medium · CVSS 6.5 · Published 2026-05-29

Technologies: shopper/framework (Packagist). Vendors: Packagist, Shopper Labs.

Executive brief

Shopper, an e-commerce platform framework, contained a flaw where administrative settings for payments, currencies, and shipping carriers were not properly protected. This allowed any user with basic access to the admin panel to disable payment methods, change currency exchange rates, or delete shipping options. Such actions could effectively shut down a store's checkout process or cause financial discrepancies by altering product pricing.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Shopper admin panel. The application rendered inline toggles and per-record actions (enable, disable, edit, delete) for PaymentMethods, Currencies, and Carriers without verifying if the authenticated user possessed the required granular permissions. An attacker with low-level authenticated access to the admin panel could exploit this to perform unauthorized state changes, leading to a denial of service for the checkout process or loss of pricing integrity. The issue is resolved in version 2.8.0 by implementing explicit permission checks (edit_payment_methods, edit_currencies, edit_carriers) for these actions.

Affected products

  • Shopper Labs Shopper Framework < 2.8.0

Timeline

  • 2026-05-20: disclosed: Initial disclosure by reporter
  • 2026-05-29: advisory: NVD publication date
  • 2026-06-05: patched: GitHub Advisory published and fix confirmed in v2.8.0

References

Related threats