Description
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used by sibling sub-forms. An authenticated staff user with browse_products can invoke the Livewire store action and replace the thumbnail and gallery images for a product whose Media component was initialized, even without product-edit permission. The product binding is locked, so the attacker cannot redirect the update to an arbitrary product through client-side ID substitution, and the impact is limited to products whose edit pages were loaded. This issue is fixed in version 2.9.2.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Apply patch
AI Analysis

Impact

Shopper, a headless e‑commerce admin panel, allows an authenticated staff user who has only browse_products permissions to call the Livewire store action for product media. Without the edit_products authorization check this action can replace the thumbnail and gallery images for a product whose Media component was initialized. The flaw is a missing authorization control (CWE‑862) that permits unauthorized modification of product assets while the product binding remains locked, limiting the effect only to products whose edit pages were already loaded.

Affected Systems

Shopper labs’ Shopper product, versions prior to 2.9.2—including 2.9.1 and earlier—are affected. The vulnerability is resolved in Shopper 2.9.2 and later releases.

Risk and Exploitability

The CVSS score of 6.5 places the flaw in the medium severity range, and the EPSS score of < 1% indicates a very low probability of exploitation in the wild. The issue is not listed in the CISA KEV catalog. Exploitation requires an authenticated staff user with browse_products permission who can access a product edit page. The impact is confined to the replacement of product thumbnail and gallery images for products whose edit page was previously loaded, rather than full administrative control, but it can still be used to deface or misrepresent products in the store.

Generated by OpenCVE AI on September 20, 2026 at 14:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Shopper to version 2.9.2 or later, where the edit_products check is restored to the Media store action.
  • If a patch cannot be applied immediately, modify the application to deny the Livewire store action for users who lack the edit_products permission, ensuring that the authorization check is enforced before image data is processed.
  • Enable application logging for media store events and monitor for suspicious image replacement activity to detect potential exploitation while remediation is pending.

Generated by OpenCVE AI on September 20, 2026 at 14:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-99h5-jhh7-v3r3 Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
History

Tue, 15 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Shopperlabs
Shopperlabs shopper
Vendors & Products Shopperlabs
Shopperlabs shopper

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used by sibling sub-forms. An authenticated staff user with browse_products can invoke the Livewire store action and replace the thumbnail and gallery images for a product whose Media component was initialized, even without product-edit permission. The product binding is locked, so the attacker cannot redirect the update to an arbitrary product through client-side ID substitution, and the impact is limited to products whose edit pages were loaded. This issue is fixed in version 2.9.2.
Title Shopper: Incomplete fix for GHSA-h4mp-g9c6-xwph: Media sub-form store() still lacks authorization
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Shopperlabs Shopper
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T19:44:12.701Z

Reserved: 2026-06-23T14:55:09.117Z

Link: CVE-2026-56830

cve-icon Vulnrichment

Updated: 2026-09-15T18:57:34.701Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T18:17:25.087

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-56830

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:45:06Z

Weaknesses