EasyStore 3.0.1 release notes - JoomShaper

Security

  • Fixed an unauthenticated guest checkout IDOR vulnerability that could expose PII. [CVE-2026-90899]
  • Fixed missing CSRF token verification in storefront product review submissions. [CVE-2026-90900]
  • Fixed an authenticated SQL injection vulnerability in media image deletion. [CVE-2026-90901]
  • Fixed an authenticated SQL injection vulnerability in coupon bulk update operations. [CVE-2026-90902]
  • Fixed missing CSRF token verification across administrator AJAX API endpoints. [CVE-2026-90903]
  • Fixed an ACL bypass vulnerability in administrator API record editing operations. [CVE-2026-90904]
  • Fixed missing CSRF token verification and access control checks in site configuration updates. [CVE-2026-90905]

Improved

  • Added a default maximum quantity limit of 9,999.
  • Improved product JSON-LD structured data for pricing, availability, and media.
  • Updated the product gallery aspect ratio to 4:5 and refined storefront gallery layout styles.
  • Added numeric constraints and step validation for tax rate configuration fields.

Fixed

  • Fixed tax calculation and breakdown discrepancies across cart, checkout, admin orders, and invoices.
  • Fixed incorrect product discount and sale badge calculations for products, variants, and bulk edits.
  • Fixed checkout default shipping method selection.
  • Fixed mini cart handling for negative quantities and related error messages.
  • Fixed Sold Out button state display in the quick cart modal.
  • Fixed broken email notification image URLs on subdomain and subfolder installations.
  • Fixed email template logo display and button text color rendering across platforms.
  • Fixed PayPal order currency and amount mismatches during checkout redirection.
  • Fixed inventory tracking behavior on the Free version.