# How to track published vulnerabilities affecting your store

> A flaw in a module or extension you use is often published publicly weeks, sometimes months, before it gets exploited at scale. That delay is the only window to act before you're affected, provided you know where to watch for it.

- Source canonique : [https://allaux.fr/en/securite/surveiller-les-failles-qui-concernent-ma-boutique](https://allaux.fr/en/securite/surveiller-les-failles-qui-concernent-ma-boutique)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Direct answer

> For WordPress and WooCommerce, the reference is the WPScan Vulnerability Database. For PrestaShop, it's the official security advisories published on the developer's GitHub repository and technical blog. For a general search by product, the NVD, run by the US NIST agency, brings together every flaw identified by a CVE.

## Three sources depending on what you use

1. **WPScan Vulnerability Database, for WordPress and WooCommerce** — A free, public database, with a usage limit on the free API, listing known flaws in WordPress core, themes and plugins, together with the fixed version to migrate to. Acquired by Automattic, it's a reference cited across the WordPress security community.
2. **Official PrestaShop security advisories** — PrestaShop publishes its security advisories on its GitHub repository and technical blog as soon as a flaw affecting the software's core is fixed, along with the version that fixes it. It's the reference source for checking whether an installed version is affected.
3. **NVD, for a general search by CVE identifier** — Run by NIST, the US standards agency, the National Vulnerability Database is the public registry where every flaw gets a CVE identifier and a description. Useful for checking a third-party component with no dedicated database of its own.

## A documented example of the gap between publication and exploitation

The flaw referenced as CVE-2023-28121 in the WooCommerce Payments plugin was fixed by the developer on 23 March 2023. Mass attacks exploiting it only began on 14 July 2023, almost four months later, according to reporting from The Hacker News and WPScan.

A site that applied the update within that window was never exposed to the mass exploitation, while a site left on the vulnerable version throughout those four months was exposed the whole time, without any symptom necessarily being visible before the attack itself.

## Staying up to date only helps for so long

> This gap between publication and mass exploitation isn't a fixed guarantee: some flaws get exploited within days, others never at scale. Following security advisories doesn't replace updating itself, then; it simply sets the priority for which one to deal with first.

## What rounds out this monitoring

- **What needs to change after a cleanup** — Update policy, access, tested backups: the habits that prevent a repeat. ([/securite/se-proteger-apres-un-nettoyage](/securite/se-proteger-apres-un-nettoyage))
- **Abandoned modules and extensions** — The real leading entry point, ahead of weak passwords. ([/securite/modules-et-extensions-abandonnes](/securite/modules-et-extensions-abandonnes))
- **Back to the security hub** — Every symptom and every known flaw, organised by what you're actually seeing. ([/securite](/securite))

## FAQ

### Is WPScan free?

Basic browsing of the Vulnerability Database is free. Access to the API for heavier automated use is subject to a usage limit on the free tier.

### Does PrestaShop have a database equivalent to WPScan?

There's no centralised community database of the same scale for PrestaShop. The developer's official advisories, published on GitHub and its technical blog, remain the reference source for the software's core.

### Do I need to track CVEs myself if I'm not technical?

Not necessarily first-hand: this monitoring can be delegated as part of ongoing maintenance. What matters is that a check happens at regular intervals rather than never.

### What if my extension is no longer maintained at all and a flaw gets published for it?

There's no fix to wait for. The answer is to remove the extension or replace it with an actively maintained alternative, not to hope for a patch that isn't coming.

### How long do I have after a flaw is published before I'm exposed?

There's no guaranteed window. The CVE-2023-28121 example shows a gap of several months between the fix and mass exploitation, but that's not a general rule that holds for every flaw.
