The eCommerce Product Catalog Plugin for WordPress has a security vulnerability that affects all versions up to 3.3.32. This vulnerability is called Reflected Cross-Site Scripting and is caused by not properly filtering and protecting user input. This means that attackers who are not logged in can insert their own malicious code into a webpage if they can get a user to click on a link.