Product Catalog Simple <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Product Catalog Simple
Minimum safe version
1.8.5
Update to 1.8.5 or later to address 14 fixable vulnerabilities
CVE-2025-62061
CVE-2025-49305
WordPress Product Catalog Simple Plugin <= 1.7.11 is vulnerable to Cross Site Scripting (XSS)
Product Catalog Simple < 1.7.6 - Cross-Site Request Forgery via ic_system_status
WordPress Product Catalog Simple Plugin <= 1.7.6 is vulnerable to Sensitive Data Exposure
WordPress Product Catalog Simple Plugin <= 1.7.5 is vulnerable to Cross Site Request Forgery (CSRF)
Product Catalog Simple <= 1.7.5 - Cross-Site Request Forgery via ic_system_status
CVE-2020-36743
CVE-2021-4342
CVE-2023-29388
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
Multiple Plugins/Themes - Cross-Site Request Forgery (CSRF)
WordPress Product Catalog Simple plugin <= 1.5.12 - Cross-Site Request Forgery (CSRF) vulnerability