Impact
A missing authorization check allows an authenticated staff user who only has permission to browse collections to call the delete action or delete bulk action within the CollectionProducts component products from a collection or empty a collection entirely, thereby disrupting catalog landing pages and promotional content. The weakness is a classic missing authorization flaw (CWE‑862). The impact is loss of integrity of product data and potential availability of catalog pages.
Affected Systems
The flaw affects installations of Shopper from versions earlier than 2.9.2. It is present in the Shopper admin panel provided by Shopper Labs under the product name Shopper.
Risk and Exploitability
The CVSS score of 8.1 classifies this as high severity. The EPSS score is < 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely an authenticated, in-browser interaction with the Livewire component; an attacker who can log into the admin panel and has read‑ action, supply a different collection identifier, and remove items without proper permission checks.
OpenCVE Enrichment
Github GHSA