Re: they are ripe for abuse
Indeed they are, but as you stated, they are nobodies, so no impact.
Also, you're talking about web shops. These are often set up by people who have an idea, think they can program, but have no notion of security. For those types, security is the annoying stuff you have to get rid of in order to work.
As a consultant in Luxembourg for the past 25 years, I can tell you that I have worked in banks, insurance companies and government organizations and I can assure you, the network security in these places is impressive. There are institutions where I do not have the right to bring my laptop.
All of these have an IT department which is staffed with people who know their stuff. Many have an Information Security Officer, and I can tell you : you do as he says.
Yes, given the nature of my skills, when I do finally get to a workstation with a working login, I do have access to the server, and to many, many databases. But if I so much as try going around and poking places I'm not supposed to do, I can kiss that customer good-bye as I will be caught out, and then thrown out.
Not every company is staffed by cowboys.