CVE-2026-77999 PUBLISHED

Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6

Assigner: Joomla
Reserved: 21.08.2026 Published: 03.09.2026 Updated: 03.09.2026

Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - The PayPal IPN listener's signature check (_validateIPN()) accepted UNVERIFIED and any non-INVALID response as valid, made its verification request with CURLOPT_SSL_VERIFYPEER disabled, and stored its verdict in a field nothing downstream ever checked — so processing continued regardless of the outcome. Separately, the paid-amount comparison only ran when mc_gross was a positive number; omitting the field from the POST body (floatval(null) == 0) skipped the check entirely. Combined with a merchant-configured receiver_email and a sequential, enumerable order id read from the custom field, an anonymous POST was enough to move a pending order straight to CONFIRMED with no payment, or force another customer's pending order to FAILED. paypalv2.php performed no amount check under any circumstances.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor j2commerce.com
Product J2Store extension for Joomla
Versions Default: unaffected
  • Version 1.0.0-3.3.21 is affected
  • Version 4.0.0-4.0.21 is affected
  • Version 4.1.0-4.1.6 is affected

Credits

  • Phil Taylor, mysites.guru finder

References

Problem Types

  • CWE-472: External Control of Assumed-Immutable Web Parameter CWE
  • CWE-602: Client-Side Enforcement of Server-Side Security CWE