The Product Catalog Simple plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This affects versions of the plugin up to 1.5.13, as it lacks the correct security measures to protect against this kind of attack. If a malicious user can get a site administrator to click a link, they can use this vulnerability to update product meta information without authorization.