Adobe has revealed that a breach occurred that affected users of Magento Marketplace, a portal the company created for buying, selling, and downloading themes and plugins for Magento-based online stores .
Adobe notified its customers by sending them an email. In that email, it stated that the breach was triggered by a vulnerability in the Magento Marketplace website, which allowed attackers to gain access to the accounts of registered users.
The attackers compromised the accounts of ordinary users, who had registered on the site to purchase plugins for Magento-based online stores, as well as plugin developers who use the portal to sell their code.
Adobe said its security team discovered the breach last week, on November 21. However, it did not disclose when the breach.
The attackers were able to gain access to various personal information of users, such as name, email address, username (MageID), billing and purchases, phone number, and some commercial data, such as developer payments from Adobe.
According to Adobe, users' account passwords and financial information were not leaked.

"We have notified all Magento Marketplace account holders who were affected," said Jason Woosley, an Adobe executive.
Woosley did not say how many accounts were affected by the breach. He said the company took the Magento Marketplace offline immediately after learning of the breach to address the vulnerability. It is now back online.
The Adobe spokesperson said the attackers were unable to cause disruptions to core Magento products and services
Magento is a cloud-based content management system (CMS) for building online stores and is one of the most popular platforms today.
