Impact
The ShopApper plugin for WooCommerce allows an authenticated user to update the stock quantity of any product through a REST endpoint without checking the user’s capabilities. This omission lets any logged‑in user—including customers or subscribers—alter inventory data, potentially causing stock shortages, erroneous sales, and revenue loss. The weakness is a classic authorization bypass, aligning with the CWE‑285 class of missing authorization.
Affected Systems
The vulnerability exists in the Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin for all releases up to and including version 0.4.62. All sites running these versions are affected.
Risk and Exploitability
Because the flaw requires only authentication, attackers who can log in as a customer or subscriber can exploit it. With no EPSS data available and no listing in the CISA KEV catalog, the exploitation probability is unclear, but the potential damage is high. The attack surface is limited to the REST API, and attackers need to construct a valid request to change stock values. The CVSS score is not provided, but given the privilege escalation nature, the risk is considered high for environments that rely on accurate inventory management.
OpenCVE Enrichment