Cross-Customer Order Duplication Vulnerability in J2Store by j2commerce.com
CVE-2026-67360
6.3MEDIUM
What is CVE-2026-67360?
A security issue in the J2Store Joomla extension allows an authenticated user to replicate another customer's order by simply supplying their order_id. This vulnerability arises due to insufficient ownership validation during session management, even though CSRF tokens are validated. This flaw can lead to unauthorized access to sensitive cart contents and customer address data, posing a significant risk to users and their personal information.
Affected Version(s)
J2Store extension for Joomla 1.0.0-3.3.20
J2Store extension for Joomla 4.0.0-4.0.20
J2Store extension for Joomla 4.1.0-4.1.5
