The eCommerce Product Catalog plugin for WordPress has a security issue in versions 3.4.3 and below. This allows hackers who are logged in and have orders manager or higher access to inject a PHP Object. There is no known way to exploit this vulnerability, but if the target system has other plugins or themes installed, it could be possible to delete files, access sensitive information, or run code.