Cross-Customer Order Duplication Vulnerability in J2Store by j2commerce.com
CVE-2026-67360

6.3MEDIUM

Key Information:

Vendor
CVE Published:
21 August 2026

What is CVE-2026-67360?

A security issue in the J2Store Joomla extension allows an authenticated user to replicate another customer's order by simply supplying their order_id. This vulnerability arises due to insufficient ownership validation during session management, even though CSRF tokens are validated. This flaw can lead to unauthorized access to sensitive cart contents and customer address data, posing a significant risk to users and their personal information.

Affected Version(s)

J2Store extension for Joomla 1.0.0-3.3.20

J2Store extension for Joomla 4.0.0-4.0.20

J2Store extension for Joomla 4.1.0-4.1.5

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Murrez
.