Description
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.
Published: 2026-07-23
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper access checks in the Joomla Easy Store extension. Logged‑in users can retrieve order and customer information for orders that do not belong to them, enabling cross‑customer data leakage. The weakness corresponds to CWE‑200 (Information Exposure) and CWE‑284 (Improper Access Control).

Affected Systems

The affected product is the Easy Store extension for Joomla from joomshaper.com, versions 1.0.0 through 2.0.1.

Risk and Exploitability

The CVSS score of 9.2 indicates a high severity. The EPSS score is below 1 %, suggesting a low likelihood of public exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user who has legitimate login access; the attacker can request order data via the front‑end or admin interfaces. The vulnerability does not require elevated privileges beyond a normal user account, but it grants access to sensitive information across customers, potentially compromising confidentiality on a site‑wide level.

Generated by OpenCVE AI on August 3, 2026 at 21:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for any updated releases of the Easy Store extension that address this vulnerability and upgrade if available.
  • Restrict order‑viewing functionality to privileged roles or adjust ACLs so that only authorized users can access customer orders.
  • Audit and monitor access logs for requests to order data to detect unauthorized retrieval attempts.

Generated by OpenCVE AI on August 3, 2026 at 21:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Joomshaper.com
Joomshaper.com easy Store Extension For Joomla
Vendors & Products Joomshaper.com
Joomshaper.com easy Store Extension For Joomla

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.
Title Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1
Weaknesses CWE-200
CWE-284
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Joomshaper.com Easy Store Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-12T13:52:10.918Z

Reserved: 2026-07-22T20:46:13.953Z

Link: CVE-2026-65760

cve-icon Vulnrichment

Updated: 2026-07-23T19:06:47.788Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T17:16:30.310

Modified: 2026-07-23T20:17:22.780

Link: CVE-2026-65760

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:30:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control