CVE-2026-78065
Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `editAddress()` redirected non-owners away only when the loaded address row had a **non-empty** `user_id` belonging to someone else. Guest-checkout address rows have an empty `user_id`, so that check never triggered for them โ any logged-in account guessing a small, sequential `address_id` got a guest customer's full name, street address, and phone number rendered prefilled into the edit form.
| CWE | CWE-639 |
| Vendor | j2commerce.com |
| Product | j2store extension for joomla |
| Published | Sep 3, 2026 |
| Last Updated | Sep 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for j2commerce.com j2store extension for joomla
Be the first to know when new unknown vulnerabilities affecting j2commerce.com j2store extension for joomla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
j2commerce.com / J2Store extension for Joomla
1.0.0-3.3.21 4.0.0-4.0.21 4.1.0-4.1.6
Credits
Phil Taylor, mysites.guru