Input validation vulnerability in eCommerce Product Catalog Plugin for WordPress 3.4.3

The eCommerce Product Catalog plugin for WordPress has a security issue in versions 3.4.3 and below. This allows hackers who are logged in and have orders manager or higher access to inject a PHP Object. There is no known way to exploit this vulnerability, but if the target system has other plugins or themes installed, it could be possible to delete files, access sensitive information, or run code.

Detected in:

eCommerce Product Catalog Plugin for WordPress fixed vulnerable versions: >= * <= 3.4.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.