Impact
The Easy Store extension for Joomla contains an unauthenticated endpoint that allows anyone with an email address to retrieve full guest shipping details from the database. Because the server performs no authentication, session validation, or ownership checks, an attacker can enumerate guest customers and harvest personally identifiable information such as names, phone numbers, and addresses. This vulnerability allows a breach of privacy and could be combined other weaknesses to facilitate further attacks.
Affected Systems
The affected product is the Easy Store extension from joomshaper.com, Joomla extension, impacting all installed versions from 1.0.0 through 3.0.0 where the legacy checkout.searchGuestUser endpoint remains active.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity risk. While an EPSS score is not available, the lack of an admission in the CISA KEV catalog suggests the exploit is not currently widely observed but could become a target. The attack vector is likely network-based, requiring only the ability to send HTTP requests to the vulnerable endpoint. Without authentication checks, enumeration of guest addresses is trivial and could be automated, leading to significant privacy exposure.
OpenCVE Enrichment