CVE-2026-77999

Summary

Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - The PayPal IPN listener's signature check (_validateIPN()) accepted UNVERIFIED and any non-INVALID response as valid, made its verification request with CURLOPT_SSL_VERIFYPEER disabled, and stored its verdict in a field nothing downstream ever checked — so processing continued regardless of the outcome. Separately, the paid-amount comparison only ran when mc_gross was a positive number; omitting the field from the POST body (floatval(null) == 0) skipped the check entirely. Combined with a merchant-configured receiver_email and a sequential, enumerable order id read from the custom field, an anonymous POST was enough to move a pending order straight to CONFIRMED with no payment, or force another customer's pending order to FAILED. paypalv2.php performed no amount check under any circumstances.

Affected Software

VendorProductVersion RangeStatus
j2commerce.comJ2Store extension for Joomla1.0.0-3.3.21affected
j2commerce.comJ2Store extension for Joomla4.0.0-4.0.21affected
j2commerce.comJ2Store extension for Joomla4.1.0-4.1.6affected

Weaknesses

  • CWE-472: CWE-472: External Control of Assumed-Immutable Web Parameter
  • CWE-602: CWE-602: Client-Side Enforcement of Server-Side Security

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References