PT-2026-97511 · Unknown · Easy Store

CVE-2026-90899

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Easy Store versions 1.0.0 through 3.0.0
Description An Insecure Direct Object Reference (IDOR) allows unauthenticated users to expose Personally Identifiable Information (PII). The 'checkout.searchGuestUser' endpoint permits querying guest checkout records by providing an email address. Because the server lacks authentication, session validation, or ownership checks, it returns full shipping details—including full name, phone number, street address, city, postal code, and country—from the # easystore guests table. An attacker can use email lists to enumerate guest customers and harvest this sensitive data.
Recommendations Update Easy Store to a version where the unauthenticated server-side guest lookup endpoint has been removed and autofill functionality has been migrated to client-side localStorage.

Fix

IDOR

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90899

Affected Products

Easy Store