Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

OrdaSoft Joomla extensions affected by two critical flaws

Two OrdaSoft Joomla extensions contain unauthenticated vulnerabilities: an SQL injection in Simple Membership and an access-control flaw in Touch Slider.

Research published by mySites.guru says Simple Membership is affected from 1.0.0 through releases before 7.4.0. The SQL injection in its login-check handler is tracked as CVE-2026-102782 and carries a CVSS 4.0 score of 9.3, rated Critical.

Touch Slider versions 1.0.0 through 5.4.5 are also affected. Its unauthenticated access-control weakness, which can allow slides to be deleted or replaced, is identified as CVE-2026-102781. It has a CVSS score of 6.9, rated Medium. The report does not confirm that either issue has been exploited.

  • Update Simple Membership to 7.4.0 or later.
  • Update Touch Slider to 5.4.6 or later.
  • If Touch Slider cannot be updated promptly, unpublish or uninstall it.

Administrators unable to update Simple Membership should disable the component if member logins are not essential, or block requests using its login-check task until remediation is possible.

Originally reported by mySites.guru.