PT-2026-97511 · Unknown · Easy Store
CVE-2026-90899
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Easy Store versions 1.0.0 through 3.0.0
Description
An Insecure Direct Object Reference (IDOR) allows unauthenticated users to expose Personally Identifiable Information (PII). The 'checkout.searchGuestUser' endpoint permits querying guest checkout records by providing an email address. Because the server lacks authentication, session validation, or ownership checks, it returns full shipping details—including full name, phone number, street address, city, postal code, and country—from the # easystore guests table. An attacker can use email lists to enumerate guest customers and harvest this sensitive data.
Recommendations
Update Easy Store to a version where the unauthenticated server-side guest lookup endpoint has been removed and autofill functionality has been migrated to client-side localStorage.
Fix
IDOR
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Easy Store