The eCommerce Product Catalog Plugin for WordPress is at risk of a security issue called Cross-Site Request Forgery. This means that anyone, even without an account, can potentially reset the password of an administrator or customer by tricking the site administrator into clicking a link. This vulnerability exists in all versions of the plugin, including 3.3.43.