eCommerce Product Catalog <= 3.4.3 - Authenticated (Orders manager+) PHP Object Injection
eCommerce Product Catalog Plugin for WordPress
Minimum safe version
3.4.4
Update to 3.4.4 or later to address 31 fixable vulnerabilities
CVE-2024-12771
CVE-2024-32558
CVE-2024-32437
WordPress eCommerce Product Catalog Plugin <= 3.3.26 is vulnerable to Sensitive Data Exposure
CVE-2023-5979
CVE-2023-47839
WordPress eCommerce Product Catalog Plugin <= 3.3.25 is vulnerable to Cross Site Request Forgery (CSRF)
eCommerce Product Catalog for WordPress <= 3.3.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
eCommerce Product Catalog for WordPress <= 3.3.25 - Cross-Site Request Forgery
eCommerce Product Catalog Plugin for WordPress < 3.0.71 - Reflected XSS
eCommerce Product Catalog Plugin for WordPress < 3.0.72 - Reflected XSS via AJAX
eCommerce Product Catalog Plugin for WordPress < 3.0.72 - Reflected XSS
CVE-2021-4392
CVE-2021-4393
CVE-2021-4342
WordPress eCommerce Product Catalog Plugin <= 3.3.8 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-25049
eCommerce Product Catalog < 3.0.18 - CSRF Nonce Bypass
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
eCommerce Product Catalog Plugin for WordPress <= 3.0.70 - Reflected Cross-Site Scripting
eCommerce Product Catalog Plugin for WordPress <= 3.0.69 - Reflected Cross-Site Scripting
eCommerce Product Catalog <= 3.0.71 - Reflected Cross-Site Scripting
eCommerce Product Catalog <= 3.0.71 - Reflected Cross-Site Scripting
WordPress eCommerce Product Catalog plugin <= 3.0.71 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress eCommerce Product Catalog plugin <= 3.0.71 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress eCommerce Product Catalog Plugin for WordPress plugin <= 3.0.70 - Reflected Cross-Site Scripting (XSS) vulnerability
Multiple Plugins/Themes - Cross-Site Request Forgery (CSRF)
WordPress eCommerce Product Catalog plugin <= 2.9.43 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress eCommerce Product Catalog plugin <= 3.0.17 - Cross-Site Request Forgery (CSRF) vulnerability
CVE-2021-24875