PrestaShop Plunder: How a Facebook Plugin is Leaving Your Credit Cards Exposed
A Facebook plugin for PrestaShop has an SQL injection vulnerability, exposing users’ credit card information. Friends-of-Presta warns that pkfacebook’s flaw is actively exploited. Despite claims of a fix, users should update pkfacebook and strengthen security measures.

Hot Take:
Who knew a Facebook plugin could turn your online store into a “grab-and-go” convenience store—except the only ones grabbing are cybercriminals, and they’re walking away with your customers’ credit card info!
Key Points:
- SQL injection vulnerability found in pkfacebook plugin for PrestaShop.
- Flaw tracked as CVE-2024-36680, actively exploited to install credit card skimmers.
- Promokit claims to have fixed the issue but offers no proof.
- 300,000 online stores potentially affected; users urged to assume vulnerability.
- Recommended fixes include updating the plugin and enhancing security measures.
Already a member? Log in here