Impact
Any order unauthenticated denial‑of‑service against the order processing pipeline. The flaw allows attackers to mass‑fail pending orders, disrupting revenue and forcing manual reprocessing, or to flip already‑fulfilled orders back to FAILED, creating operational confusion, unwarranted refunds or cancellations and increased customer‑support workload.
Affected Systems
The vulnerability affects the J2Store extension for Joomla from j2commerce.com, covering all releases from 1.0.0 to 3.3.2, 4.0.0 to 4.0.22, and 4.1.0 to 4.1.7. Systems running these versions should be reviewed for potential exploitation.
Risk and Exploitability
With a CVSS score of 8.7, this vulnerability possesses high severity. The EPSS score of less than 1% indicates a very low probability that it is being actively exploited currently, although the lack of a KEV listing does not reduce its operational risk. Attackers can exploit it from any unauthenticated access to the order interface; no special privileges or sensitive data are required beyond the ability to trigger the status‑change operation, making it a straightforward path for mass order failure or reversion of completed orders.
OpenCVE Enrichment