CSRF and Access Control Issues in Joomla Extension by JoomShaper
CVE-2026-90905

7.2HIGH

Key Information:

Vendor
CVE Published:
23 September 2026

What is CVE-2026-90905?

The Easy Store extension for Joomla, developed by JoomShaper, has a vulnerability that allows unauthorized changes to site configuration settings. The issue arises from the absence of anti-CSRF token validation and inadequate administrative access controls. This means that a malicious actor could potentially exploit this weakness to alter critical site parameters—such as the sender name and email address—using forged requests, thereby compromising the integrity of communications emanating from the site. The issue has been addressed by implementing stricter token verification processes and confirming administrative permissions to ensure that only authorized users can make changes to the configuration.

Affected Version(s)

Easy Store extension for Joomla 1.0.0-3.0.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.