The defective Shopify plugin puts hundreds of websites at risk of invasive attacks – Find out how to stay safe


  • Consentik, a cookie consent application and consent management for Shopify, has retained sensitive data in an open archive
  • The archive was available for at least 100 days, if not more
  • It included site analysis data, Shopify personal access tokens and Facebook authentication tokens

A major and renowned Shopify plugin, said sensitive information for months, exhibiting hundreds of electronic commerce companies to all kinds of risks, experts warned.

Safety researchers of Cyberness Spotted the flight and helped plug the hole after discovering a Kafka server accessible to the public which contained sensitive data from Consentik.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top