Known security flaws, explained from what you're seeing
Nobody types "CVE-2024-XXXXX" into Google when their store stops working properly. They type "my site redirects to a casino site" or "strange orders are appearing in my back office". This section starts from what you're actually seeing and works back to the technical flaw, never the other way round.
How to use this section
Each page below starts from a concrete symptom or a category of flaw and explains, in plain language, what's actually happening, how to check whether you're affected, and what to do. None of these pages give an attack method, a working exploit, or a tool for targeting a site: the content is strictly defensive, written for a merchant who needs to understand their situation and act, not for someone looking to exploit a flaw.
When a vulnerability identifier (CVE) or a specific version is cited, it's because it was verified against a reliable public source, named in the text. Where a technical point is uncertain, the page stays deliberately general rather than making an unverified claim: wrong information about a security flaw is worse than no information, because it can make you believe you're protected when you aren't.
What you've noticed on your store
-
My site redirects to an unknown site
A visitor lands on the store and ends up elsewhere, sometimes only on mobile.
-
Spam pages in my Google results
Pages you never wrote appear under your own domain name.
-
My host has suspended my site
An email announces a suspension for "suspicious activity", with no other detail.
-
Suspicious orders or customer accounts
A burst of failed orders, or dozens of accounts created overnight.
-
An unknown file on the server
A strangely named PHP file sitting in a folder that should only hold images.
-
My site is sending emails I didn't write
Customers report a promotional message coming from your domain.
-
My antivirus blocks my own site
Chrome or a visitor's antivirus shows a danger warning.
Understanding the kind of flaw involved
-
SQL injections
What they actually are, and how to check whether your store is affected.
-
Abandoned modules and extensions
The real first entry point, ahead of a weak password.
-
Admin passwords and shared access
Human flaws, not technical ones, and among the easiest to fix.
-
File permissions on shared hosting
How an infection can spread from one site to another on the same server.
-
End-of-life PHP versions
A version that "still works" no longer receives any security fix.
Check, react, clean up, protect
-
Checking if your site is compromised, without paid tools
The free checks to run before considering a paid audit.
-
What to do in the first two hours
The exact order of priorities once the doubt has just been confirmed.
-
Cleaning up an infected site
The method, and why restoring a backup isn't always enough.
-
Staying protected after a cleanup
What has to change structurally to avoid a repeat.
-
Tracking published vulnerabilities
Where to follow flaws affecting what you actually use.
In this section
-
I’ve received an email asking me to install a security patch
The message looks like an official alert, it names a vulnerability and offers a file to install: this is exactly the scenario of…
-
The payment form appears twice during checkout
A customer enters their card, the page reloads, and the real payment form asks for the same details again: that double entry is…
-
An admin account I never created has appeared
It is the opening move in almost every recent WordPress intrusion: create an administrator account, sometimes hidden from the…
-
My shop name is displaying text I never wrote
A fragment of code turns up in the footer, in the browser tab or in order emails: the configuration value holding your shop name…
-
My email provider has disabled my API key
The service that sends your order emails cuts your key without warning, or reports usage coming from somewhere else. Very often…
-
My visitors see a fake "prove you're human" page
Your customers describe a verification screen asking them to paste a command into their own computer, while you see nothing…
-
I clean my site and the infection is back the next day
You delete the flagged files, everything looks normal for a few hours, then the exact same problem is back: a reload point is…
-
A simple form on my site became the way in
A contact, quote or price calculation form stays an area where anyone can write whatever they like, with no account and no…
-
My back office behaves oddly when I open a customer message
A customer service page that reloads by itself, a window that opens, a field that fills in on its own: content sent by a visitor…
-
A customer ended up logged into someone else’s account
A shopper sees orders that aren’t theirs, or you get a complaint about an address nobody ever entered: that is an authentication…
-
WordPress updated itself: what happened
A security update pushed onto every installation doesn’t happen every year. When it does, it isn’t a precaution: it means the…
-
My PrestaShop store was hacked and no password ever leaked
No shared access, no weak password, no infected workstation, and yet foreign code on the server: the heaviest flaws of recent…
-
A plugin update installed a backdoor
Merchants are told to update everything without delay. There is a rare but real case where the official update is the vector…
-
A flaw has just been published: how long do I have
The question isn’t rhetorical, and the measured answer is shorter than most merchants assume. Here are the delays actually…
-
My module’s publisher is gone and the flaw will never be fixed
Some security advisories end with “no fix will be released”. Updating is then off the table, and disabling the module is not…
-
I paid for my plugins: am I better protected
The instinct is reasonable: a publisher who gets paid can afford to have its code reviewed. The figures published by the bodies…
-
My host says their firewall is enough: is that true
An application firewall blocks a share of attacks, and that share is measurable. Knowing what it catches — and above all what it…
-
A "critical 9.8 out of 10" flaw: what that score means for me
Every security advisory carries a score, an identifier and a good deal of expert vocabulary. Only three parts of that record…
-
What customer data could actually have left my site
After a breach, the most urgent question isn’t how to clean up — it’s what got out. The answer depends on the entry point, and it…
-
Do I have to tell my customers and the regulator after a hack
A compromised online shop handles names, addresses and purchase histories. The GDPR sets out precisely what the data controller…
-
My site redirects to an unknown site
A visitor lands on your store and ends up somewhere else, sometimes only on mobile or only when coming from Google: this…
-
Spam pages have appeared in my search results
You type your store's name into Google and pages you never wrote show up, often on topics unrelated to your business: this is a…
-
My host has suspended my site for suspicious activity
An email from the host announces a shutdown for "suspicious activity", with no further detail: in the vast majority of cases, the…
-
Suspicious orders or customer accounts are appearing
Orders placed with different bank cards within minutes, or dozens of customer accounts created the same night: this is almost…
-
Unknown file on the server
A PHP file with a strange name, or one that mimics a core CMS file, sitting in a folder that should only hold images or exports…
-
The site sends unknown emails
Customers report receiving a promotional message or a suspicious follow-up from your domain, or your host flags an unusual…
-
Antivirus or browser blocks the site
Chrome shows a red "dangerous site" screen, or your visitors' antivirus cuts access to your store: this isn't a Google mistake…
-
SQL injections: what they are, and how to check if you’re affected
This is the most frequently exploited flaw against online stores, because it reaches the database directly: orders, customers…
-
Abandoned modules and extensions: the real number one attack vector
Before a weak password, before a badly configured server, the most common entry point remains a module or extension nobody…
-
Admin passwords and shared access
A password reused across three services, FTP access given to a provider and never revoked, an admin account created "just to help…
-
Poorly set file permissions on shared hosting
A folder or file left too open on a server shared by dozens of other sites can be enough to spread an infection from one site to…
-
PHP versions past end of life
A PHP version that’s no longer maintained stops receiving any security patches, even if a critical flaw is found in it after its…
-
Checking if your site is compromised, without paid tools
Before paying for an audit, four free checks already give a fairly clear picture, provided you know what each one actually…
-
What to do in the two hours after a compromise
The very first hours aren't for a deep cleanup, but for stopping the ongoing exploitation and preserving what will later help…
-
Cleaning up an infected site: the method, and why restoring isn't enough
Reinstalling a backup looks like the fastest shortcut, but that speed only pays off if the backup is genuinely clean. Here's how…
-
Staying protected for good after a cleanup
A site that's cleaned up but brought back online exactly as it was before often ends up in the same state within a few months…
-
Tracking published vulnerabilities affecting your store
A flaw in a module or extension you use is often published publicly weeks, sometimes months, before it gets exploited at scale…
Frequently asked questions
How do I know which page in this section applies to me?
Are these pages enough to clean my site myself?
Why are some of the flaws mentioned several years old?
Does this section only cover PrestaShop and WordPress?
What if no page matches my exact situation?
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.