What the vulnerability does
01Description
Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders.
Explanation of Vulnerability in Simple Terms
02Summary
The Easy Store extension for Joomla contains an access control flaw that allows unauthenticated attackers to modify data on the site. The vulnerability affects versions 1.0.0 through 2.0.1. No authentication or user interaction is required to exploit this issue. Site administrators should update to a version newer than 2.0.1 as soon as a patch becomes available.
What an attacker can do
03Attacker Capabilities
Modify or alter data on the site without logging in.
Potential impact on your site
04Site Impact
Attackers can change site content, settings, or user data without permission.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
July 23, 2026
CVE published
July 24, 2026
Record updated