Unauthenticated Payment Manipulation in Joomla Extension by JoomShaper
CVE-2026-65759

8.7HIGH

Key Information:

Vendor
CVE Published:
23 July 2026

What is CVE-2026-65759?

The Easy Store extension from JoomShaper is susceptible to an unauthenticated payment and order forgery vulnerability. In versions 1.0.0 to 2.0.1, attackers can exploit the extension's handling of client-side input that processes sensitive order and payment information. This flaw allows malicious individuals to manipulate the states of arbitrary orders without authentication, posing significant security risks for online transactions and data integrity.

Affected Version(s)

Easy Store extension for Joomla 1.0.0-2.0.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor
.