The eCommerce Product Catalog Plugin for WordPress, up to and including version 3.0.17, is vulnerable to Cross-Site Request Forgery. This means that unauthenticated attackers may be able to save manual digital orders without actually being logged in by tricking a site administrator into clicking on a link. This is because the save() function is missing or incorrect nonce validation.