CVE-2026-16569
Received Received - Intake

Unauthorized Stock Quantity Update in WooCommerce Mobile App

Vulnerability report for CVE-2026-16569, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: WPScan

Description

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock quantity of arbitrary products.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
shopapper woocommerce to 0.4.66 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper access control flaw in the ShopApper Mobile App Builder Service for WooCommerce WordPress plugin. It allows any authenticated user, including subscribers or customers, to update the stock quantity of arbitrary products through a REST endpoint without proper capability checks.

Detection Guidance

Check if the ShopApper plugin version is 0.4.66 or earlier. Inspect WordPress REST API logs for unauthorized stock-update requests from non-admin users. Look for unusual stock quantity changes in product records.

Impact Analysis

An attacker could manipulate product stock levels, potentially causing inventory discrepancies, financial losses, or disruptions in order fulfillment. This could lead to customer dissatisfaction or operational issues for online stores using the affected plugin.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves improper access control in a WordPress plugin rather than data breaches or unauthorized access to sensitive information.

Mitigation Strategies

Update the ShopApper plugin to the latest version immediately. Review and restrict user roles to ensure only authorized personnel can modify stock levels. Monitor product stock changes for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16569. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart