PrestaShop: Resolving Module Security Vulnerability Issues

Edit – To learn more about the risks, trends and, above all, the solutions to put in place to secure your e-commerce business in 2022, discover all the useful information in our article “How to Fight Against Module Vulnerabilities?“
Being able to maintain the security of your PrestaShop e-commerce site should be a priority. Indeed, as we mentioned in a previous article dedicated to the security of your site, the open source solution can sometimes fall prey to malicious individuals.
Module security vulnerabilities on PrestaShop come in several levels of severity, from the most trivial to the most critical. Very often these vulnerabilities are found in add-on modules or in tools used by modules.
These vulnerabilities are often reported to the module’s publisher before malicious individuals can exploit them. The module’s publisher is then responsible for finding a solution and providing an update.
Being informed of a security issue related to a module on your PrestaShop store
This is a complex matter that is unfortunately not made easy on module platforms or by publishers.
We invite you to check the module’s page on the Addons platform in order to review the notes for the latest version. If a security fix is available, it will be indicated (in English). For example:

Warning:
However, only the notes for the latest version are visible on the module’s page on Addons. It will therefore not be possible for you to know whether version 5.2.10 (to use the example above) includes a security fix.
This is why it’s complex to know whether a module needs to be updated for security reasons. To avoid taking any risk, it’s therefore recommended to keep your modules up to date to benefit from the latest fixes. This comes at a cost, since module licenses expire by default after 3 months.
Modules purchased on Addons have the advantage of being able to indicate that an update is available directly on your PrestaShop back office.

This allows you to check what the update includes in its latest version.
However, you won’t get this notification if the module comes from your theme or if it was downloaded from another platform. It’s therefore important to pay particular attention to these modules.
Aware of these difficulties, we regularly inform our clients whenever a module security flaw is discovered. Our clients who have chosen 7724 hosting also have the opportunity to have a team and monitoring system that raises an alert in the event of an intrusion involving known vulnerabilities.
The identified security issues
The year 2020 was marked by an increase in attacks on PrestaShop. More and more bots are tasked with scanning sites in search of vulnerabilities. If a vulnerability is detected by the bot, then a person steps in to exploit it. This makes exploiting vulnerabilities very simple, and it becomes achievable by people without necessarily having very advanced technical knowledge. The bots are regularly updated to include the list of vulnerable modules.
Several of these modules have been heavily exploited for several months, according to the data we’ve gathered during our interventions to restore infected sites. Among others, we frequently come across the XsamXadoo malware (bajatax_xsamado) exploiting the following modules in addition to PHPUnit vulnerabilities:
-
- Sample Data Install (sampledatainstall)
-
- Smart Blog (smartblog)
-
- File Explorer pro (explorerpro)
-
- Colorpictures
If you have one of these modules, you should act immediately and check with us or your technical team which actions need to be taken.
The list above is far from exhaustive. To date, we have identified around a hundred modules frequently exploited for vulnerabilities by other malware. It’s often necessary to run a more thorough scan of the store in order to check all modules.
Vulnerabilities are generally always the same. The attacker exploits a vulnerable file within the module, allowing them to inject a script or PHP code, or to exploit an SQL injection.
| Update from 09/30/2020: We detected another vulnerability this week. It’s a flaw present in the FreePay module by Oyst. The consequence of the vulnerability is the hijacking of your customers’ payment information. It is therefore imperative to remove this module. |
| Update from 01/22/2021: A new vulnerability has been detected by our teams. The flaw is present in the Abandoned Cart Reminder Pro – cartabandonmentpro module, from version 1.4 to 1.7 (inclusive). The vulnerability allows infected code to be injected into the module, through the RoxyFileman file editor, which is accessible to everyone and unprotected. Updating the module is necessary to fix this issue, or removing the module from your FTP if it’s not in use. Manual intervention is therefore required. Contact us |
Resolving module security vulnerabilities
Updating the module in question resolves the vulnerability issue, if a fix exists!
If a fix is not yet available, deactivating the module can directly resolve the issue. However, some modules, often older ones or those not from the Addons platform, remain exploitable even once deactivated.
To reduce the risk as much as possible, the best practice is to never leave an unused module on your server.
Other, more complex vulnerabilities require the intervention of specialized developers.
In any case, it’s strongly recommended that you turn to your technical team to check what actions need to be put in place to fix the issue.
Our developers work every day to address security issues on our clients’ sites.
![]() |
The Security Pack can handle all types of PrestaShop module vulnerabilities. As part of this Pack, we take care of:
|
Don’t hesitate to contact us to find out more, because the security of your PrestaShop is our specialty.
Contact us!

