Unauthenticated PayPal Callback Forgery in J2Store by j2commerce.com
CVE-2026-77999
8.7HIGH
What is CVE-2026-77999?
The vulnerability in the J2Store extension allows unauthenticated users to exploit weaknesses in the PayPal IPN listener, leading to order confirmation fraud. The _validateIPN() function improperly validates responses and disables SSL verification, enabling attackers to forge payment confirmations. This flaw can be exploited to change an order status without proper payment verification or manipulate other customers' orders by using specifically crafted POST requests.
Affected Version(s)
J2Store extension for Joomla 1.0.0-3.3.21
J2Store extension for Joomla 4.0.0-4.0.21
J2Store extension for Joomla 4.1.0-4.1.6
