CVE-2026-65759
Deferred Deferred - Pending Action

Unauthenticated Payment/Order Forgery in Easy Store Joomla Extension

Vulnerability report for CVE-2026-65759, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: Joomla! Project

Description

Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-23
AI Q&A
2026-07-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
joomshaper easy_store to 2.0.1 (inc)
joomshaper easystore to 2.0.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated payment/order forgery in the Easy Store Joomla extension versions 1.0.0 to 2.0.1. It allows attackers to manipulate order and payment states without authentication by processing client-side input. This could enable attackers to mark orders as paid without actual payment, leading to free goods dispatch.

Detection Guidance

Check if the EasyStore extension version is below 2.0.2 by inspecting the Joomla admin panel or running SQL queries on the database to verify the installed version. Look for unauthorized order state changes or unexpected payment confirmations in order logs.

Impact Analysis

This vulnerability allows attackers to forge orders and payments without authentication. This could result in financial losses for store owners due to unpaid orders being marked as paid. It also exposes sensitive customer data like names, emails, addresses, and phone numbers through unauthorized access to invoices and orders.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to sensitive customer data such as names, emails, addresses, and phone numbers. Exposure of such data violates privacy and security requirements under these regulations.

Mitigation Strategies

Update the EasyStore extension to version 2.0.2 or later immediately. Review order logs for suspicious activity, such as orders marked as paid without transactions. Ensure no unauthorized access to customer data has occurred.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65759. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart