Kam eben per Mail von JoomShaper
Hi,
We've just released EasyStore v2.0.2, a critical security release. We strongly recommend all site administrators update to version 2.0.2 immediately to ensure your store and customer data remain fully secure.
Note: This update applies to both EasyStore Pro and EasyStore Free users.
Why this matters:
This release closes three vulnerabilities that could have exposed customer data or your store's checkout flow.
What we fixed:
Order repayment tampering: Attackers could manipulate parameters during order repayments. We've locked this down with CSRF protection, server-side verification, and ownership checks.
SQL injection risk in product filtering: Catalog sorting parameters are now strictly allow-listed.
Customer data exposure (IDOR): Order details and invoice views now properly verify that customers can only see their own data.
What to do:
Log in to your Joomla admin panel.
Go to System → Update → Extensions.
Select EasyStore, click Update.
Or, download the latest package from the JoomShaper site and install manually via the Extension Manager.
Before you update:
Back up your site, as always.
Other notable enhancements:
Beyond the security fixes, this update also includes the following enhancements:
Added customization options for product specification display (Pro only)
Added tracking URL support in the order detail summary (admin and storefront)
Added custom class support for all addons in settings, with default classes included (Pro only)
Improved range slider validation and value handling
Updated rating descriptions and added missing language strings
Resolved coupon condition issues
Fixed an addon settings error on the product list (Pro only)
Product gallery images now update correctly when switching variants