logo

Facebook PrestaShop module exploited to steal credit cards

ID: c04f592b-06eb-591e-9924-8a621270b47e

STIX ID: report--c04f592b-06eb-591e-9924-8a621270b47e

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-06-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Hackers are actively exploiting an SQL injection vulnerability (CVE-2024-36680) in the pkfacebook premium Facebook module for PrestaShop to install web skimmers that steal customers' payment card data; Friends-of-Presta published a proof-of-concept and warned of widespread exploitation while patch availability remains unclear, and mitigations such as upgrading, WAF rules, and configuration hardening are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.