A vulnerability, which was classified as problematic, was found in Shopper Labs Shopper up to 2.7.x. This impacts the function
Customers/Create::store/DNS1DFacade::getBarcodeHTML of the component Livewire Components. The manipulation of the argument password/barcode results in improper privilege management.
This vulnerability is identified as CVE-2026-47743. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.