Impact
The Easy Store extension for Joomla accepts critical order and payment information entirely from client‑side input, allowing attackers to forge requests that change the state of arbitrary orders. This flaw represents an Improper Access Control weakness (CWE‑284), as unauthenticated users can manipulate payment and order states. An unauthenticated user can, by crafting appropriate POST data, mark orders as paid, cancel payments, or otherwise alter transaction status, leading to financial loss, falsified records, and erosion of customer trust.
Affected Systems
Joomshaper Easy Store extension for Joomla, versions 1.0.0 through 2.0.1.
Risk and Exploitability
The CVSS score of 8.7 signals a high‑severity flaw, while an EPSS score of less than 1% indicates the exploitation probability is currently low and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is remote over HTTP(S) to the order/payment endpoints; this is inferred from the description that the flaw allows unauthenticated manipulation of client‑side data. The attacker need only send specially crafted client requests and does not require prior authentication. The weakness, classified as CWE‑284 (Improper Access Control), permits manipulation of order state across the entire system, presenting a serious risk for any site running vulnerable versions.
OpenCVE Enrichment