The Product Catalog Simple plugin for WordPress is not secure in versions up to 1.7.7. Attackers that do not have permission to access the website can gain access to sensitive information such as full product details by importing and exporting Product CSV files.