The eCommerce Product Catalog Plugin for WordPress plugin is vulnerable to a type of attack called Cross-Site Request Forgery in all versions up to 3.3.26. This means that unauthenticated attackers, who can convince a site administrator to click on a link, can delete, reset, or reassign products and categories on the website without permission due to a lack of protection when product and category settings are handled.