CVE-2026-16569: ShopApper <= 0.4.62 - Subscriber+ Arbitrary Product Stock Update
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock quantity of arbitrary products.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user can exploit it, including low-privileged customer or subscriber accounts. The affected REST operation does not verify that the user has permission to manage product stock.
What can an attacker change?
An authenticated attacker can update the stock quantity of arbitrary products through the affected REST endpoint. This could allow them to alter product availability or inventory records.
Which versions are affected?
The issue affects the ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through version 0.4.62.