Unauthenticated PII Exposure in Easy Store Extension by Joomla Vendor
CVE-2026-90899

8.2HIGH

Key Information:

Vendor
CVE Published:
23 September 2026

What is CVE-2026-90899?

The Easy Store extension by Joomla has a vulnerability that allows unauthenticated attackers to query guest checkout records using just an email address. This exposes comprehensive shipping details, including full names, phone numbers, addresses, and more from the backend database without any authentication or session validation. Attackers can exploit this flaw to enumerate guest customers by iterating through potential email addresses, thereby harvesting sensitive Personally Identifiable Information (PII). The issue has been addressed by fully removing the unauthenticated server-side guest lookup endpoint and implementing a secure autofill functionality within the client-side, backed by user consent.

Affected Version(s)

Easy Store extension for Joomla 1.0.0-3.0.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.