The eCommerce Product Catalog plugin for WordPress is vulnerable to a type of attack called Reflected Cross-Site Scripting. Versions of the plugin up to 3.0.71 are affected because they do not properly sanitize and escape input. This means that an attacker could insert malicious web scripts into pages if they can get a user to click on a link.