Security
EasyStore 2.0.2 fixes three Joomla security flaws
JoomShaper’s EasyStore ecommerce extension for Joomla contained three serious vulnerabilities before version 2.0.2, including flaws that could expose customer records or alter orders without authentication.
mySites.guru published the research after privately reporting the issues to JoomShaper. The affected releases are 2.0.1 and all earlier versions; administrators should update to 2.0.2 immediately.
CVE-2026-65759: unauthenticated order forgery and field manipulation, rated High with a CVSS 4.0 score of 8.7.CVE-2026-65760: broken access control allowing logged-in customers to view other customers’ orders and invoices, rated Critical at 9.2.CVE-2026-65761: unauthenticated SQL injection through product sorting, rated Critical at 9.3.
The SQL injection could expose Joomla accounts, password hashes, site secrets and customer data, while the order flaw could mark purchases as paid. The report documents testing on a research installation and does not report exploitation in the wild.
After upgrading, administrators whose sites ran a vulnerable release should assess potential data exposure and consider rotating the Joomla secret, API keys and other sensitive credentials. The update closes all three issues.
Originally reported by mySites.guru.