CVE-2026-67360: Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5

Published Aug 21, 2026
·
Updated

Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's orderid to copy their cart contents and address data into the attacker's session. The CSRF token was validated but ownership was not checked.

Affected Software

1 affected component
j2commerce.com J2Store>=1.0.0<=3.3.20, >=4.0.0<=4.0.20, >=4.1.0<=4.1.5

Event History

Aug 21, 2026
CVE Published
via MITRE·07:16 PM
Data Sourced
via MITRE·07:16 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be an authenticated J2Store user and be able to provide another customer's order_id. The issue allows copying that customer's cart contents and address data into the attacker's own session.

2

Does CSRF protection prevent exploitation?

No. The CSRF token was validated, but the affected functionality did not verify that the supplied order_id belonged to the authenticated user.

3

Which J2Store versions are affected?

Affected versions are 1.0.0 through 3.3.20, 4.0.0 through 4.0.20, and 4.1.0 through 4.1.5.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203