CSRF and Access Control Issues in Joomla Extension by JoomShaper
CVE-2026-90905
What is CVE-2026-90905?
The Easy Store extension for Joomla, developed by JoomShaper, has a vulnerability that allows unauthorized changes to site configuration settings. The issue arises from the absence of anti-CSRF token validation and inadequate administrative access controls. This means that a malicious actor could potentially exploit this weakness to alter critical site parameters—such as the sender name and email address—using forged requests, thereby compromising the integrity of communications emanating from the site. The issue has been addressed by implementing stricter token verification processes and confirming administrative permissions to ensure that only authorized users can make changes to the configuration.
Affected Version(s)
Easy Store extension for Joomla 1.0.0-3.0.0
