top of page
perceptive_background_267k.jpg

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an …

Published:

28 May 2026 at 22:00:00

Alert date:

29 May 2026 at 20:03:36

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

CVE-2026-47740 affects Shopper, a headless e-commerce admin panel, prior to version 2.8.0. The vulnerability allows authenticated low-privilege users to perform order management actions without proper permissions. Users with read-only access could cancel orders, mark them as paid or complete, capture payments, and modify shipments. The capturePayment action could trigger actual payment service provider captures, resulting in real funds movement. This represents a critical privilege escalation that could lead to financial fraud and order manipulation.

Technical details

Mitigation steps:

Affected products:

Shopper

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page