PrestaShop Plunder: How a Facebook Plugin is Leaving Your Credit Cards Exposed

A Facebook plugin for PrestaShop has an SQL injection vulnerability, exposing users’ credit card information. Friends-of-Presta warns that pkfacebook’s flaw is actively exploited. Despite claims of a fix, users should update pkfacebook and strengthen security measures.

Hot Take:

Who knew a Facebook plugin could turn your online store into a “grab-and-go” convenience store—except the only ones grabbing are cybercriminals, and they’re walking away with your customers’ credit card info!

Key Points:

  • SQL injection vulnerability found in pkfacebook plugin for PrestaShop.
  • Flaw tracked as CVE-2024-36680, actively exploited to install credit card skimmers.
  • Promokit claims to have fixed the issue but offers no proof.
  • 300,000 online stores potentially affected; users urged to assume vulnerability.
  • Recommended fixes include updating the plugin and enhancing security measures.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here