EasyStore 3.0 SECURITY HOLES - Forum | JoomShaper
Staff replied EasyStore

EasyStore 3.0 SECURITY HOLES

Asked by Stuart Clark 2 weeks ago Last activity 1 week ago

I'm not even surprised to find that EasyStore 3.0 continued to have HUGE SECURITY BUGS, even after previous updates to address them!

To this end, EasyStore 3.0.1 has now been released, fixing SEVEN CVE entries!!! - Yes - SEVEN!

Unfortunately, JoomShaper haven't yet fixed ANY of the bugs which make EasyStore 3.0 unusable in a production website!

11 replies

Stuart Clark Asked this

From the changelog (so no guarantee it is accurate):

  • Fixed an unauthenticated guest checkout IDOR vulnerability that could expose PII. [CVE-2026-90899]
  • Fixed missing CSRF token verification in storefront product review submissions. [CVE-2026-90900]
  • Fixed an authenticated SQL injection vulnerability in media image deletion. [CVE-2026-90901]
  • Fixed an authenticated SQL injection vulnerability in coupon bulk update operations. [CVE-2026-90902]
  • Fixed missing CSRF token verification across administrator AJAX API endpoints. [CVE-2026-90903]
  • Fixed an ACL bypass vulnerability in administrator API record editing operations. [CVE-2026-90904]
  • Fixed missing CSRF token verification and access control checks in site configuration updates. [CVE-2026-90905]
Ofi Khan Staff

Hello Stuart Clark,

From the changelog (so no guarantee it is accurate):

With due respect, your response is disrespectful. We have submitted the CVEs to Joomla! Security Team. It will be approved very soon. We put exact information on the changelog. We guarantee it. But humans can make mistakes. If there is any issue with the changelog, let us know and we will fix it.

Unfortunately, JoomShaper haven't yet fixed ANY of the bugs which make EasyStore 3.0 unusable in a production website!

I have discussed your issues with my teammates. None of the issues are major issues. Few of the issues are already solved. If you still face issues, then we are here to help.

I hope that we will be respectful in our communication.

Best regards

Stuart Clark Asked this

Hello Ofi Khan

With due respect, your response is disrespectful. We have submitted the CVEs to Joomla! Security Team. It will be approved very soon. We put exact information on the changelog. We guarantee it. But humans can make mistakes. If there is any issue with the changelog, let us know and we will fix it.

I'm sorry, but recent history has shown us that many JoomShaper products have included MANY security holes, a lot of which haven't been admitted to or even referenced in changelogs. The whole debacle with SP Page Builder, over numerous releases backs this up.

SECURITY HAS NOT HAD THE FOCUS IT DESERVES

I have discussed your issues with my teammates. None of the issues are major issues. Few of the issues are already solved. If you still face issues, then we are here to help.

I, and other customers, have been asking for fixes for OVER 2 YEARS! To hear you say that "none of the issues are major" just shows a complete disregard for your customers needs and backs up the feeling that JoomShaper are not interested in actually supporting customers!

IF JOOMSHAPER ARE INCAPABLE OF RESOLVING BUGS WHICH HAVE EXISTED FOR OVER 2 YEARS, EASYSTORE IS NOT FIT FOR PURPOSE AND SO YOU NEED TO REFUND EVERY CUSTOMER!

I hope that YOU will be respectful in your communication with customers!

Ofi Khan Staff

We take security issues seriously and fixing all the concerns as soon as possible. There are differences in breaking issues or bugs and customer requirements or feature requests. We cannot satisfy all your requirements. The management also have some decision power.

IF JOOMSHAPER ARE INCAPABLE OF RESOLVING BUGS

Please do not label it like this. If your requirements are not fulfilled, then consider this:
It is not getting much attention or not enough requests. Some of the issues are requested only by you. We have to check every pros and cons and alignment of the product with our vision. After that we decide to include or not include the feature.

SO YOU NEED TO REFUND EVERY CUSTOMER!

Not every customer asks for a refund. Those who asked, we have given according to our refund policy.

Stuart Clark Asked this

Rather than trying to tell customers (me) that they are either wrong or that their issues do not matter, which is what you have said above - WHY NOT consider actually engaging with your customers to see what they really want, rather than what you THINK they want???

I point you to this thread - https://www.joomshaper.com/forum/question/42223 - where you have REPEATEDLY REFUSED to engage by publishing a roadmap for EasyStore.

I point you to this thread - https://www.joomshaper.com/forum/question/34627 - which shows 2 YEAR OLD BUGS which have yet to be resolved. This thread also shows a FAILED COMMITMENT TO PUBLISH A ROADMAP FOR EASYSTORE

I point you to this thread - https://www.joomshaper.com/forum/question/33814 - in which YOU made various commitments to ensure bugs got fixed and requested features added - you've failed in a lot of cases to implement those commitments!

SO, once again - please be respectful in your communication with customers, rather than trying to attack them for pointing out what HASN'T been provided, as previously promised!

Ofi Khan Staff

Please do not share links. Just point out your issues here. It is not possible to go through the long forum links and search for your issues. It would be helpful and easier to solve if you just say it. Ask yourself what you want and share here. I will directly go to the developer's desk with your issues.

But you have to keep in mind that we might not fulfill all your expectations. Accept it. We have our vision for the product.

For roadmaps, as stated earlier, we will not share the roadmaps to the end users.

Stuart Clark Asked this

The LINKS are to other "Questions" on JoomShaper's own forum!

Are you trying to tell me you're TOO LAZY to read what customers have posted to you???

...

Let me remind you of what you demanded in your first comment... "I hope that we will be respectful in our communication". - WHY ARE YOU NOT BEING RESPECTFUL IN THE SLIGHTEST???

Ofi Khan Staff

I understand your point, and I apologize for how my previous response came across. My intention was not to suggest that we are unwilling to read your forum posts or that we consider them unimportant.

You are absolutely welcome to reference the existing forum discussions. I am only asking that you also briefly identify the specific issue or change you want from each one. That will allow me to consolidate your feedback and communicate it clearly to the development team.

Regarding your expectations, I will make sure they are communicated to the team. At the same time, I want to be transparent that we cannot promise that every requested change will be implemented. Product decisions are ultimately based on our product direction, technical considerations, and priorities.

I appreciate you taking the time to explain your concerns, and I will make sure the points you raise are properly communicated to the team.

Stuart Clark Asked this

Your lack of engagement is truly AMAZING!

Here's the simple list, with screenshots, so you don't bother having to look into anything further!

BUG – It is now possible to place a "guest order" using the same email address as one already used to create a Joomla user, and then the order does NOT show up under the user

Currently, EasyStore handles guest orders and orders placed through a user account separately. I have discussed this behavior with our development team, and we will improve this flow in a future update.

The above shows EasyStore 3.0 is NOT PRODUCTION READY - It is a BETA

BUG – Create user account process is NOT available unless Guest Orders are enabled

Currently, when Guest Checkout is disabled and a user proceeds to the checkout page without being logged in, they are redirected to the login page.

We have discussed this workflow with our development team, and the account/checkout flow will be improved in a future update.

The above shows EasyStore 3.0 is NOT PRODUCTION READY - It is a BETA

BUG – Upon installation, product Variation Libraries get overwritten or added to, making a mess of layouts

Could you please share a screenshot showing how the Product Variation Libraries are being overwritten or added to after the EasyStore installation/upgrade? This will help us understand exactly what is happening on your website and investigate the issue more accurately.

This is SIMPLE testing. I'm not sure why you're incapable of performing it yourselves!

https://prnt.sc/OFxKS7R6QS8- - Variation Libraries in EasyStore 2.1.0

https://prnt.sc/ZgkZ0sGc7fog - Size options 1/2 (EasyStore 2.1.0)

https://prnt.sc/u7XED1M7B0st - Size options 2/2 (EasyStore 2.1.0)

https://prnt.sc/vIjnx0FT_gbq - Variation Libaries AFTER update to EasyStore 3.0

https://prnt.sc/MQdxhOHEVSMJ - Size options 2/2 AFTER update to EasyStore 3.0

BUG – Buy Now button does NOT adhere to site CSS rules

The Buy Now button currently inherits the template's secondary button design when no specific button design has been configured for the SP Page Builder addon.

If you have a specific example where the button is not following the expected styling, please share a screenshot so we can investigate it further.

https://prnt.sc/vk41MO8H3qMN - CSS NOT FOLLOWED ON BUY IT NOW BUTTON

BUG – Default email templates are reset and image links are broken

Could you please let us know which specific images are broken? You mentioned that the Store icons are affected, so a screenshot of the broken icons or the affected email template would be helpful for us to identify the issue.

https://prnt.sc/LCP-qdw2oiOl - Where do YOU think the broken images might be??? This is SIMPLE

Ofi Khan Staff

Thanks for your clarification of the issues. Now we can communicate better. I have sat with my team to discuss about the issues. My team has already informed you about the issue progress. However, I will mention it here too:

BUG – It is now possible to place a "guest order" using the same email address as one already used to create a Joomla user, and then the order does NOT show up under the user

It will be fixed soon. I have asked the developer team to act fast.

BUG – Create user account process is NOT available unless Guest Orders are enabled

Since we have to change the design, it will take some more time to implement. Right now, the issue is not fatal or break anything. It is a bad UX.

BUG – Upon installation, product Variation Libraries get overwritten or added to, making a mess of layouts

Sorry, I checked it with my team. The variation library seems to be the okay on both versions. I would request you to share a screencast of this issue.

BUG – Buy Now button does NOT adhere to site CSS rules

This is not an issue. Due to CSS class used, the button gets the secondary button CSS from the templates. You can change it if you use SP Page Builder for EasyStore pages. There you can design the button as per your need. If you do not use SP Page Builder there, then you have to use Custom CSS to change it.

BUG – Default email templates are reset and image links are broken

This is very unfortunate that on the recent update the templates are reset. We will be careful about this on the future releases. The broken image issue is already fixed. Please check it on the current version.

Stuart Clark Asked this

BUG – It is now possible to place a "guest order" using the same email address as one already used to create a Joomla user, and then the order does NOT show up under the user

When is soon??? Soon is not a valid release date!

BUG – Create user account process is NOT available unless Guest Orders are enabled

You developed this feature, so in reality you missed an obvious issue. Again, we need a timescale for when this will be fixed!

BUG – Upon installation, product Variation Libraries get overwritten or added to, making a mess of layouts

I've posted the screenshots of this NUMEROUS TIMES - here they are again - LOOK AT THEM!

https://prnt.sc/OFxKS7R6QS8- - Variation Libraries in EasyStore 2.1.0

https://prnt.sc/ZgkZ0sGc7fog - Size options 1/2 (EasyStore 2.1.0)

https://prnt.sc/u7XED1M7B0st - Size options 2/2 (EasyStore 2.1.0)

https://prnt.sc/vIjnx0FT_gbq - Variation Libaries AFTER update to EasyStore 3.0

https://prnt.sc/MQdxhOHEVSMJ - Size options 2/2 AFTER update to EasyStore 3.0

BUG – Buy Now button does NOT adhere to site CSS rules

Out of the box it does not do what is expected - you are forcing the customer to work out and resolve this issue themselves!

BUG – Default email templates are reset and image links are broken

You've admitted it yourself - this was AGAIN due to a lack of testing by JoomShaper
Your CUSTOMERS ***should not be expected to rectify sloppy implementation and testing by JoomShaper!

There are OTHER bugs in EasyStore 3.0 which have been reported by other people - I don't see fixes for those either in the latest release notes!

Ofi Khan Staff

It is now possible to place a "guest order" using the same email address as one already used to create a Joomla user, and then the order does NOT show up under the user

We need time for design dependency. No estimated time is available.

Create user account process is NOT available unless Guest Orders are enabled

We need time for design dependency. No estimated time is available.

Upon installation, product Variation Libraries get overwritten or added to, making a mess of layouts

That boxes had no use cases and this is why these are removed. There are some default variations which cannot be deleted. Not an issue

Buy Now button does NOT adhere to site CSS rules

Not an issue

Default email templates are reset and image links are broken

It will be fixed in the next version

Unable to delete product images

It is solved on current version. Just download and install. It will be fixed.

Discounts are displayed with 5 decimal places (e.g. 10.00000%)

It will be fixed in the next version

Stuart Clark Asked this

Well, your formatting is impossible to understand; and your statements show a complete lack of testing!

It is now possible to place a "guest order" using the same email address as one already used to create a Joomla user, and then the order does NOT show up under the user

This is a SERIOUS DESIGN FLAW which you should have spotted during the initial design / implementation of the feature. IT MAKES THE FEATURE IMPOSSIBLE TO USE ON EXISTING STORES WITH GUEST CUSTOMERS. The fact you failed to do so shows very sloppy coding and testing!

Create user account process is NOT available unless Guest Orders are enabled

This is a DESIGN FLAW which you should have spotted during the initial design / implementation of the feature. The fact you failed to do so shows very sloppy coding and testing!

Upon installation, product Variation Libraries get overwritten or added to, making a mess of layouts

Your ridiculous statements show you STILL haven't bothered testing this fully. Your incompetence in this situation is unacceptable!

.... what happened to you being respectful to customers???

Log in to reply.