What the vulnerability does
01Description
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.
Explanation of Vulnerability in Simple Terms
02Summary
The Easy Store extension for Joomla contains an access control flaw that allows unauthenticated attackers to read sensitive data via network requests. No user interaction is required. The vulnerability affects versions 1.0.0 through 2.0.1. Site administrators should update to a version newer than 2.0.1 when available.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the site without logging in.
Potential impact on your site
04Site Impact
Confidential information may be exposed to anyone on the internet.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
July 23, 2026
CVE published
July 24, 2026
Record updated