SQL Injection Vulnerability in Easy Store Extension by JoomShaper
CVE-2026-90901

8.6HIGH

Key Information:

Vendor
CVE Published:
23 September 2026

What is CVE-2026-90901?

The Easy Store extension by JoomShaper contains a vulnerability that allows authenticated users to perform SQL injection attacks via the checkout.searchGuestUser endpoint. By simply supplying an email address, attackers are able to access sensitive guest checkout records, including full shipping information. This lack of proper authentication and session validation opens doors for attackers to enumerate guest customers and exploit Personally Identifiable Information (PII). The issue has been mitigated by completely removing the vulnerable server-side endpoint and implementing client-side safeguards that rely on user consent.

Affected Version(s)

Easy Store extension for Joomla 1.0.0-3.0.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.