WordPress · J2Store · CVE-2026-67359
**Name of the Vulnerable Software and Affected Versions**
J2Store versions 1.0.0 through 3.3.20
J2Store versions 4.0.0 through 4.0.20
J2Store versions 4.1.0 through 4.1.5
**Description**
An unauthenticated visitor can access the full checkout confirmation page of an order, exposing sensitive data such as line items, prices, and totals. This occurs when a user provides an arbitrary `order id` as a query parameter.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.