SQL Injection Vulnerability in Easy Store Extension by JoomShaper
CVE-2026-90901
8.6HIGH
What is CVE-2026-90901?
The Easy Store extension by JoomShaper contains a vulnerability that allows authenticated users to perform SQL injection attacks via the checkout.searchGuestUser endpoint. By simply supplying an email address, attackers are able to access sensitive guest checkout records, including full shipping information. This lack of proper authentication and session validation opens doors for attackers to enumerate guest customers and exploit Personally Identifiable Information (PII). The issue has been mitigated by completely removing the vulnerable server-side endpoint and implementing client-side safeguards that rely on user consent.
Affected Version(s)
Easy Store extension for Joomla 1.0.0-3.0.0
