Impact
Shopper, a headless e‑commerce admin panel, had a flaw in older versions that allowed any authenticated user to see and use inline toggle actions for PaymentMethods, Currencies and Carriers without checking per‑action permissions. The flaw lets a low‑privilege user disable every payment method, change or remove the default currency, or disable carriers. The resulting denial of checkout and loss of pricing integrity can cripple store operations and revenue.
Affected Systems
Shopper Labs’ Shopper application was affected in every release prior to 2.8.0. Users running these versions should verify their installation against the published changelog for 2.8.0, which contains the authorization fix.
Risk and Exploitability
The CVSS score of 6.5 rates the vulnerability as medium severity. No EPSS score is publicly available, and the vulnerability is not listed in CISA’s KEV catalog. Because it is exploitable by any authenticated panel user, the risk is amplified in environments where low‑privilege accounts are granted administrative access. Immediate patching or restriction of privileged actions is therefore recommended to prevent a full checkout shutdown.
OpenCVE Enrichment
Github GHSA