Description
Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders.
Published: 2026-07-23
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Easy Store extension for Joomla accepts critical order and payment information entirely from client‑side input, allowing attackers to forge requests that change the state of arbitrary orders. This flaw represents an Improper Access Control weakness (CWE‑284), as unauthenticated users can manipulate payment and order states. An unauthenticated user can, by crafting appropriate POST data, mark orders as paid, cancel payments, or otherwise alter transaction status, leading to financial loss, falsified records, and erosion of customer trust.

Affected Systems

Joomshaper Easy Store extension for Joomla, versions 1.0.0 through 2.0.1.

Risk and Exploitability

The CVSS score of 8.7 signals a high‑severity flaw, while an EPSS score of less than 1% indicates the exploitation probability is currently low and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is remote over HTTP(S) to the order/payment endpoints; this is inferred from the description that the flaw allows unauthenticated manipulation of client‑side data. The attacker need only send specially crafted client requests and does not require prior authentication. The weakness, classified as CWE‑284 (Improper Access Control), permits manipulation of order state across the entire system, presenting a serious risk for any site running vulnerable versions.

Generated by OpenCVE AI on August 3, 2026 at 21:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Easy Store extension release that contains the patch for the input validation issue from joomshaper.com.
  • Until the update can be applied, configure the web server or application to block or require authentication for the order creation and payment submission endpoints, preventing unauthenticated access.
  • Verify that server‑side code enforces strict validation and access controls for all order and payment data, ensuring that state changes are only possible through authenticated, authorized processes.

Generated by OpenCVE AI on August 3, 2026 at 21:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Joomshaper.com
Joomshaper.com easy Store Extension For Joomla
Vendors & Products Joomshaper.com
Joomshaper.com easy Store Extension For Joomla

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders.
Title Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Joomshaper.com Easy Store Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-12T13:57:43.201Z

Reserved: 2026-07-22T20:46:13.953Z

Link: CVE-2026-65759

cve-icon Vulnrichment

Updated: 2026-07-23T19:05:58.752Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T17:16:30.190

Modified: 2026-07-23T20:17:22.667

Link: CVE-2026-65759

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:30:05Z

Weaknesses