The eCommerce Product Catalog plugin for WordPress has a security vulnerability that could allow someone to inject malicious code into a web page. This vulnerability affects versions up to 3.0.70 of the plugin, and can be exploited if an attacker can get a user to do something like click on a link. The malicious code could then run on the user’s computer or device. To protect yourself, make sure you have the latest version of the plugin installed.