The eCommerce Product Catalog plugin for WordPress has a security issue that affects versions 3.0.71 and lower. The issue is called Reflected Cross-Site Scripting, and it happens when the plugin does not properly check and filter the data it receives. This means that a malicious entity can inject web scripts into web pages if they can trick an unsuspecting user into clicking on a link.