Multiple Livewire components in the admin panel allowed an authenticated low-privilege user to mutate data without the required permission:
read_orders only and did not require edit_orders. capturePayment could trigger an actual PSP capture.browse_orders only.store(), so any authenticated panel user could mutate product data without edit_products.Settings/Team/Index had no mount() authorization at all — any authenticated user could create roles and delete other users.Settings/Team/RolePermission gated its write actions on the read-only view_users permission, allowing privilege escalation via the RBAC system itself.PaymentMethods, Currencies, Carriers table toggles and per-record actions had no per-action permission check.Customers/Create::store() re-passed a Hidden _password form field into the create payload.Several public Eloquent model properties on Livewire components were not #[Locked], allowing client-side ID tampering.
A stored XSS surface existed on the product barcode field, which is rendered through DNS1DFacade::getBarcodeHTML() with {!! !!}.
Fixed in v2.8.0. Upgrade via:
composer require shopper/admin:^2.8 shopper/cart:^2.8 shopper/core:^2.8
php artisan migrate
None. Upgrade to v2.8.0.
{
"cwe_ids": [
"CWE-285",
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-18T16:34:23Z",
"nvd_published_at": "2026-05-29T19:16:25Z",
"severity": "HIGH"
}