Impact
Any order unauthenticated denial‑of‑service against the order processing pipeline. The flaw allows attackers to mass‑fail pending orders, disrupting revenue and forcing manual reprocessing, or to flip already‑fulfilled orders back to FAILED, creating operational confusion, unwarranted refunds or cancellations and increased customer‑support workload.
Affected Systems
The vulnerability affects the J2Store extension for Joomla from j2commerce.com, covering all releases from 1.0.0 to 3.3.2, 4.0.0 to 4.0.22, and 4.1.0 to 4.1.7. Systems running these versions should be reviewed for potential exploitation.
Risk and Exploitability
With a the issue is High, and the% indicates a very low exploitation probability, though the lack of a KEV listing does not diminish its seriousness. The attack vector is unauthenticated; any user who can reach the order interface can manipulate the status of orders. No privileges or sensitive data are required beyond the ability to invoke the order status change operation.
OpenCVE Enrichment