What is CVE-2026-65759?
CVE-2026-65759 is an unauthenticated payment/order forgery vulnerability in the Easy Store extension (versions 1.0.0-2.0.1) for Joomla. The flaw arises from processing client-side input for order and payment states, allowing unauthenticated attackers to manipulate payment statuses of arbitrary orders. Affected sites should immediately update the extension to the latest version or temporarily disable it.
Azərbaycanca: CVE-2026-65759, Joomla üçün Easy Store (1.0.0-2.0.1 versiyaları) genişlənməsində autentifikasiya olunmamış ödəniş/sifariş saxtakarlığı zəifliyidir. Bu boşluq müştəri tərəfindən göndərilən ödəniş və sifariş statusu məlumatlarının işlənməsi səbəbindən yaranır və autentifikasiya olunmamış hücumçulara istənilən sifarişin ödəniş statusunu manipulyasiya etməyə imkan verir. Təsirə məruz qalan saytlar dərhal genişlənməni ən son versiyaya yeniləməli və ya müvəqqəti olaraq deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which Joomla extension is affected by CVE-2026-65759?
CVE-2026-65759 affects the Easy Store extension for Joomla, versions 1.0.0 through 2.0.1.
What can an attacker achieve by exploiting CVE-2026-65759?
An unauthenticated attacker can manipulate the payment status of any order.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.