The eCommerce Product Catalog Plugin for WordPress is currently vulnerable to Cross-Site Request Forgery in versions up to 2.9.43. This means that if an unauthorized user can persuade a site administrator to click on a malicious link, they can change product data without the administrator’s permission. This is because the plugin does not have enough protection to stop this from happening.