PT-2026-82388 · WordPress · Shopapper Mobile App Builder Service
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ShopApper Mobile App Builder Service for WooCommerce WordPress plugin versions prior to 0.4.63
Description
The plugin fails to verify user permissions before performing stock-update operations via a REST endpoint. This allows any authenticated user, including those with low-level roles like customer or subscriber, to modify the stock quantity of any product.
Recommendations
Update the plugin to version 0.4.63 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopapper Mobile App Builder Service