CVE-2026-65759

Severity CVSS v4.0:
HIGH
Type:
CWE-284 Improper Access Control
Publication date:
23/07/2026
Last modified:
23/07/2026

Description

Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders.