EasyStore for Joomla versions 1.0.0 through 3.0.0 are affected by seven documented security vulnerabilities, including an unauthenticated exposure of guest checkout shipping details. Store owners should update to EasyStore 3.0.1 or later, then review backend access, mail settings, and relevant logs.
EasyStore installations below version 3.0.1 should be treated as needing a security update. Seven CVEs cover guest-customer data exposure, cross-site request forgery (CSRF), SQL injection, and access-control weaknesses; the documented remediation is EasyStore 3.0.1 or later.
EasyStore Joomla extension vulnerabilities: the immediate action
The confirmed affected range is EasyStore for Joomla 1.0.0 through 3.0.0. The seven documented issues are resolved in EasyStore 3.0.1, so administrators running 3.0.0 or an earlier release should plan and perform the upgrade as soon as practical.
Before changing a production ecommerce site, take a tested backup of the Joomla files and database, record the installed EasyStore version, and confirm that the backup can be restored. Obtain the current package through the EasyStore product page or your established vendor delivery channel. After the upgrade, verify the installed version in Joomla, test a normal customer journey, and check the administrator functions used by your store.
The most urgent risk area is CVE-2026-90899. It allowed an unauthenticated party to retrieve guest checkout shipping details using an email address. That can expose personally identifiable information (PII), including customer shipping details, without requiring a Joomla login. EasyStore 3.0.1 removes the unauthenticated lookup responsible for this risk.
The seven fixed EasyStore vulnerabilities
The vulnerabilities do not all have the same preconditions or consequences. One concerns unauthenticated access to guest information; several others require an authenticated, privileged backend user or interaction with a logged-in user. That distinction matters when prioritising follow-up checks, but it does not change the patch recommendation: update every affected installation to 3.0.1 or later.
| Extension | CVE | Authentication | Issue | Affected versions | Recommended version | CVSS 4.0 | CISA KEV |
|---|---|---|---|---|---|---|---|
| EasyStore | CVE-2026-90899 | None | Guest checkout PII exposure | 1.0.0–3.0.0 | 3.0.1 or later | 8.2 High | Not listed |
| EasyStore | CVE-2026-90900 | Not specified | Missing CSRF protection on product review submissions | 1.0.0–3.0.0 | 3.0.1 or later | 5.3 Medium | Not listed |
| EasyStore | CVE-2026-90901 | Authenticated, privileged | SQL injection in media image deletion | 1.0.0–3.0.0 | 3.0.1 or later | 8.6 High | Not listed |
| EasyStore | CVE-2026-90902 | Authenticated, privileged | SQL injection in coupon bulk updates | 1.0.0–3.0.0 | 3.0.1 or later | 8.2 High | Not listed |
| EasyStore | CVE-2026-90903 | Authenticated | Missing CSRF protection on administrator AJAX API actions | 1.0.0–3.0.0 | 3.0.1 or later | 7.2 High | Not listed |
| EasyStore | CVE-2026-90904 | Authenticated | ACL bypass in record editing | 1.0.0–3.0.0 | 3.0.1 or later | 8.6 High | Not listed |
| EasyStore | CVE-2026-90905 | Authenticated | Missing CSRF and access control on configuration updates | 1.0.0–3.0.0 | 3.0.1 or later | 7.2 High | Not listed |
The table uses CVSS 4.0 scores assigned by the Joomla CNA. Scores help describe the assessed severity of a vulnerability; they are not evidence that a vulnerability has been used against a particular site.
Customer data exposure in guest checkout
CVE-2026-90899 is the only issue in this set described as requiring no authentication. An exposed guest-checkout lookup could return full shipping details for guest customers based only on an email address. For ecommerce operators, this creates a meaningful privacy and data-harvesting risk even where backend accounts are well controlled.
Updating removes the unauthenticated lookup. Because the issue concerns customer information, administrators should also retain and review available web-server and application logs for unusual patterns involving guest checkout around the period the affected release was in use. A lack of unusual records does not prove that no data was accessed, particularly where logging was incomplete.
CSRF protections and administrator actions
CSRF occurs when a browser that is already authenticated to a site is induced to send an unwanted request. The affected user does not necessarily realise that an action has been submitted. CVE-2026-90900 concerns product-review submission, while CVE-2026-90903 concerns state-changing administrator AJAX API actions. CVE-2026-90905 combines missing CSRF protection with inadequate authorisation on a configuration update that could alter core Joomla mail settings.
Version 3.0.1 restores or centralises CSRF validation for the documented actions. The operational lesson remains useful after patching: avoid visiting untrusted sites while logged in to Joomla administrator, keep administrator sessions short, and ensure custom EasyStore templates preserve CSRF token handling for forms they override.
SQL injection and access control
CVE-2026-90901 is an authenticated, privileged SQL injection issue in media image deletion. It is not a second guest-data disclosure. Its public record contains a description discrepancy, so the vulnerability is best understood according to its title and the supported technical classification: a privileged backend operation could manipulate database queries before the fix.
CVE-2026-90902 similarly affects coupon bulk updates, where handling of supplied IDs permitted SQL injection for a privileged authenticated user. The correction in 3.0.1 enforces integer handling and parameterised query construction. CVE-2026-90904 is an access-control issue: authenticated backend users could edit records despite Joomla ACL restrictions because the relevant edit check did not enforce the intended permissions.
These three issues reinforce a practical Joomla administration rule: do not grant broad backend access merely because a user needs one store task. Review EasyStore and Joomla permissions so that coupon management, media administration, configuration access, and general editing privileges are assigned only where genuinely required.
Upgrade and verification checklist
Use the following order to reduce both exposure and the risk of an avoidable production problem.
- Identify affected sites. Inventory every Joomla installation that uses EasyStore. Confirm whether its installed version is in the affected 1.0.0–3.0.0 range, including sites maintained for clients, staging instances, and less-visible regional stores.
- Create and test a backup. Back up files and the database before the update. For agencies, record the extension version, update time, and responsible administrator in the client change log.
- Update to EasyStore 3.0.1 or later. Do not assume that an unverified intermediate build contains these fixes. Confirm the upgraded version in Joomla after installation.
- Perform focused functional tests. Test a standard customer purchase flow, guest checkout where used, product reviews, coupon administration, media tasks, and store administration. Confirm that normal authorised users can complete their legitimate duties and that role boundaries still behave as intended.
- Audit backend users and groups. Remove stale administrator accounts, review users with high-privilege EasyStore or Joomla permissions, and apply least privilege. Pay particular attention to staff who can edit records, manage coupons, change configuration, or work with media.
- Check mail configuration. Review Joomla sender name and sender email settings against the approved configuration for the site. CVE-2026-90905 could affect mail configuration in vulnerable releases, so unexpected changes warrant investigation.
- Review available logs. Look for unusual access patterns associated with guest checkout, administrator AJAX activity, coupon management, media deletion, and configuration updates. Preserve relevant logs before rotation and follow your incident-response process if unexpected activity is found.
For sites holding substantial guest-order data, consider whether internal privacy, contractual, or regulatory procedures require a documented assessment of the exposure period. The verified records establish that the data exposure existed in affected releases; they do not establish that a particular store’s data was accessed.
Severity, NVD status, and exploitation evidence
The Joomla CNA assigned CVSS 4.0 scores ranging from 5.3 Medium to 8.6 High. CVSS is a severity framework: it estimates characteristics and potential impact under defined conditions. It should guide prioritisation, but it is not the same as evidence of observed exploitation.
All seven CVEs are currently marked Awaiting Analysis by the National Vulnerability Database (NVD). For example, the NVD record for CVE-2026-90899 reflects that status. NVD may refine details as its review progresses. The CVSS values used in this article are the Joomla CNA's CVSS 4.0 scores, not a claim that NVD analysis has been completed.
None of CVE-2026-90899 through CVE-2026-90905 are currently listed in CISA's Known Exploited Vulnerabilities catalog, and there is no authoritative confirmation that these EasyStore issues are being actively exploited. That absence does not mean exploitation is impossible or that affected stores can safely defer maintenance. It means only that CISA has not confirmed exploitation for these CVEs at this time.
What developers and agencies should retain from this advisory
The fixes address several security boundaries that deserve regression testing whenever an ecommerce extension is customised: public access to guest data, CSRF validation on state-changing requests, parameterised database queries, and Joomla ACL enforcement. A custom override can unintentionally bypass a security control if it replaces a form or controller flow without carrying forward its token and authorisation checks.
For agency maintenance plans, make extension-version inventory and prompt security updates routine rather than exceptional. Record which client stores permit guest checkout, which staff have backend access, and who approves configuration changes. This produces a faster, more reliable response when a vulnerability affects an extension used across multiple sites.
The immediate conclusion is straightforward: if an EasyStore site is on 3.0.0 or an earlier affected version, update it to 3.0.1 or later, validate the store's essential workflows, and complete the focused permission and log review described above.
Add comment