CVE-2026-90901: Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0

Published Sep 23, 2026
·
Updated

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest checkout records solely by supplying an email address. The server returned complete shipping details (full name, phone number, street address, city, postal code, and country) directly from the #easystoreguests table with no authentication, session validation, or ownership checks. An unauthenticated attacker could iterate through email lists to enumerate guest customers and harvest sensitive Personally Identifiable Information (PII). Resolved by removing the unauthenticated server-side guest lookup endpoint entirely and migrating autofill functionality to client-side localStorage protected by explicit user consent.

Affected Software

1 affected component
JoomShaper Easy Store>=1.0.0<=3.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Remove the unauthenticated guest lookup endpoint, including the checkout.searchGuestUser endpoint.

    Easy Store unauthenticated server-side guest lookup endpoint = disabled/removed
  2. Configuration

    Migrate autofill functionality from server-side guest-record lookup to client-side localStorage protected by explicit user consent.

    Easy Store guest checkout autofill = client-side localStorage with explicit user consent

Event History

Sep 23, 2026
CVE Published
via MITRE·06:42 PM
Data Sourced
via MITRE·06:42 PM
DescriptionWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit the exposed guest-record lookup?

An unauthenticated attacker can query the endpoint without a session, authentication, or ownership validation. They only need email addresses to look up guest checkout records.

2

What information could be disclosed?

The endpoint returned full name, phone number, street address, city, postal code, and country from the guest checkout table. Attackers could iterate through email lists to enumerate and harvest guest customer PII.

3

Which versions are affected?

The supplied version range is Easy Store 1.0.0 through 3.0.0. The data states the issue was resolved by removing the unauthenticated server-side guest lookup endpoint.

4

What configuration condition is required for exposure?

The affected behavior was an unauthenticated server-side guest lookup at the checkout.searchGuestUser endpoint. No additional configuration requirement is provided.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203