GHSA-243p-f3cv-c5wh: Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
highvulnerability
security
Summary
A security flaw in Shopper's admin interface allows staff members with read-only browse permissions to perform destructive bulk actions they shouldn't be able to do. Specifically, five admin pages are missing authorization checks (->authorize(...) permission gates) on their bulk action features, letting browse-only staff delete all attributes and tags, or disable all brands, categories, and suppliers. This is a type of authorization bypass (CWE-862, missing authorization) with a CVSS severity score of 8.1 High.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Patch Available
Yes
Disclosure Date
September 11, 2026
Classification
Attack SophisticationTrivial
Affected Packages
shopper/framework@< 2.9.2 (fixed: 2.9.2)
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-243p-f3cv-c5wh
First tracked: September 11, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 95%