How to track published vulnerabilities affecting your store
A flaw in a module or extension you use is often published publicly weeks, sometimes months, before it gets exploited at scale. That delay is the only window to act before you're affected, provided you know where to watch for it.
Three sources depending on what you use
-
WPScan Vulnerability Database, for WordPress and WooCommerce
A free, public database, with a usage limit on the free API, listing known flaws in WordPress core, themes and plugins, together with the fixed version to migrate to. Acquired by Automattic, it's a reference cited across the WordPress security community.
-
Official PrestaShop security advisories
PrestaShop publishes its security advisories on its GitHub repository and technical blog as soon as a flaw affecting the software's core is fixed, along with the version that fixes it. It's the reference source for checking whether an installed version is affected.
-
NVD, for a general search by CVE identifier
Run by NIST, the US standards agency, the National Vulnerability Database is the public registry where every flaw gets a CVE identifier and a description. Useful for checking a third-party component with no dedicated database of its own.
A documented example of the gap between publication and exploitation
The flaw referenced as CVE-2023-28121 in the WooCommerce Payments plugin was fixed by the developer on 23 March 2023. Mass attacks exploiting it only began on 14 July 2023, almost four months later, according to reporting from The Hacker News and WPScan.
A site that applied the update within that window was never exposed to the mass exploitation, while a site left on the vulnerable version throughout those four months was exposed the whole time, without any symptom necessarily being visible before the attack itself.
What rounds out this monitoring
-
What needs to change after a cleanup
Update policy, access, tested backups: the habits that prevent a repeat.
-
Abandoned modules and extensions
The real leading entry point, ahead of weak passwords.
-
Back to the security hub
Every symptom and every known flaw, organised by what you're actually seeing.
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.