CVE-2026-77999

Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - The PayPal IPN listener's signature check (`_validateIPN()`) accepted `UNVERIFIED` and any non-`INVALID` response as valid, made its verification request with `CURLOPT_SSL_VERIFYPEER` disabled, and stored its verdict in a field nothing downstream ever checked — so processing continued regardless of the outcome. Separately, the paid-amount comparison only ran when `mc_gross` was a positive number; omitting the field from the POST body (`floatval(null) == 0`) skipped the check entirely. Combined with a merchant-configured `receiver_email` and a sequential, enumerable order id read from the `custom` field, an anonymous POST was enough to move a pending order straight to `CONFIRMED` with no payment, or force another customer's pending order to `FAILED`. `paypalv2.php` performed no amount check under any circumstances.
CVSS

No CVSS.

References
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 13:06

Updated : 2026-09-03 17:30


NVD link : CVE-2026-77999

Mitre link : CVE-2026-77999

CVE.ORG link : CVE-2026-77999


JSON object : View

Products Affected

No product.

CWE
CWE-472

External Control of Assumed-Immutable Web Parameter

CWE-602

Client-Side Enforcement of Server-Side Security