Unauthenticated PII Exposure in Easy Store Extension by Joomla Vendor
CVE-2026-90899
What is CVE-2026-90899?
The Easy Store extension by Joomla has a vulnerability that allows unauthenticated attackers to query guest checkout records using just an email address. This exposes comprehensive shipping details, including full names, phone numbers, addresses, and more from the backend database without any authentication or session validation. Attackers can exploit this flaw to enumerate guest customers by iterating through potential email addresses, thereby harvesting sensitive Personally Identifiable Information (PII). The issue has been addressed by fully removing the unauthenticated server-side guest lookup endpoint and implementing a secure autofill functionality within the client-side, backed by user consent.
Affected Version(s)
Easy Store extension for Joomla 1.0.0-3.0.0
