CVE-2023-30153: Prestashop Payplug
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote attackers to execute arbitrary SQL commands via the ajax.php front controller.
Affected products
- Prestashop Payplug: from 3.6.0, before 3.8.2 (fixed in 3.8.2)
Published 2023-07-18. Last modified 2026-06-17.