Impact
This vulnerability arises from improper access checks in the Joomla Easy Store extension. Logged‑in users can retrieve order and customer information for orders that do not belong to them, enabling cross‑customer data leakage. The weakness corresponds to CWE‑200 (Information Exposure) and CWE‑284 (Improper Access Control).
Affected Systems
The affected product is the Easy Store extension for Joomla from joomshaper.com, versions 1.0.0 through 2.0.1.
Risk and Exploitability
The CVSS score of 9.2 indicates a high severity. The EPSS score is below 1 %, suggesting a low likelihood of public exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user who has legitimate login access; the attacker can request order data via the front‑end or admin interfaces. The vulnerability does not require elevated privileges beyond a normal user account, but it grants access to sensitive information across customers, potentially compromising confidentiality on a site‑wide level.
OpenCVE Enrichment