WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Ultimate Product Catalogue?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Ultimate Product Catalogue — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: ultimate-product-catalogue
  • 5000+ instalaciones activas

catalogcatalogueproductproduct catalogwoocommerce catalog

Estado de mantenimiento

  • Última versión conocida: 5.3.15
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

4 CVEs conocidos registrados para Ultimate Product Catalogue. Reportadas entre 2014 y 2026.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2021-47924 Ultimate Product Catalog [ultimate-product-catalogue] <= 5.8.2 (unfixed) Media 6,4 < 5.8.2 5.8.2 2026-05-10 ⚠ necesita actualización
CVE-2024-31921 Ultimate Product Catalog [ultimate-product-catalogue] < 5.2.16 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 5.2.16 5.2.16 2024-04-10 ✓ corregido en la última versión
CVE-2023-2711 Ultimate Product Catalog [ultimate-product-catalogue] < 5.2.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 5.2.6 5.2.6 2023-06-05 ✓ corregido en la última versión
CVE-2021-24993 Ultimate Product Catalog [ultimate-product-catalogue] < 5.0.26 Falsificación de petición en sitios cruzados (CSRF) Media 6,5 < 5.0.26 5.0.26 2022-01-06 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.26 Desconocido < 4.2.26 4.2.26 2017-10-30 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.22 Desconocido < 4.2.22 4.2.22 2017-10-03 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.3 Desconocido < 4.2.3 4.2.3 2017-06-27 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.3 Desconocido < 4.2.3 4.2.3 2017-06-27 ✓ corregido en la última versión

CVE-2021-47924

Ultimate Product Catalogue 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the price parameter. Attackers can submit POST requests to post.php with HTML/JavaScript payloads in the price field to execute arbitrary code when the product is viewed.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-31921

Update the WordPress Ultimate Product Catalogue plugin to the latest available version (at least 5.2.16). Dhabaleshwar Das discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Ultimate Product Catalogue Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 5.2.16. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-2711

The Ultimate Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2021-24993

The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change the plugin's settings for example

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.26

A vulnerability exists in UPCP_Add_To_Cart() function. There the cookie is unserialized which means an attacker can create a malicious user input to create a PHP object injection.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.22

The Ultimate Product Catalog plugin for WordPress is vulnerable to authorization bypass and Cross-Site Request Forgery in versions up to, and including 4.2.21 due to missing capability and nonce checking on various functions. This makes it possible for authenticated attackers to perform a wide variety of actions such as updating the plugin's settings and uploading arbitrary files.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.3

WordPress Ultimate Product Catalogue plugin vulnerable to SQL Injection due to unescaped $_POST[‘CatID’] Change log of the plugin doesn't indicate any fixes related to this vulnerability. We will update information soon.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.3

The Ultimate Product Catalog plugin for WordPress is vulnerable to SQL Injection via the ‘CatID’ parameter in versions before 4.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

+ 17 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
Ultimate Product Catalog [ultimate-product-catalogue] < 3.9.9 Desconocido < 3.9.9 3.9.9 2016-07-29 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 3.4 Desconocido < 3.4 3.4 2016-06-29 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 3.8.7 Desconocido < 3.8.7 3.8.7 2016-06-27 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 3.8.2 Desconocido < 3.8.2 3.8.2 2016-06-20 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 3.8.2 Desconocido < 3.8.2 3.8.2 2016-06-17 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3 Desconocido < 3.1.3 3.1.3 2015-06-07 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3 Desconocido < 3.1.3 3.1.3 2015-05-04 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3 Desconocido < 3.1.3 3.1.3 2015-04-23 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.2 Desconocido < 3.1.2 3.1.2 2015-04-22 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3 Desconocido < 3.1.3 3.1.3 2015-04-22 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.22 Desconocido < 4.2.22 4.2.22 2015-04-22 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 2.1.1 Desconocido < 2.1.1 2.1.1 2014-05-28 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.3 Desconocido < 4.2.3 4.2.3 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 3.9.9 Desconocido < 3.9.9 3.9.9 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.5 Desconocido < 3.1.5 3.1.5 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3 Desconocido < 3.1.3 3.1.3 ✓ corregido en la última versión
Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.2 Desconocido < 3.1.2 3.1.2 ✓ corregido en la última versión

Ultimate Product Catalog [ultimate-product-catalogue] < 3.9.9

This plugin is prone to an SQL injection vulnerability via ajax. It allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Ultimate Product Catalog [ultimate-product-catalogue] < 3.4

This WordPress Ultimate Membership Pro plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update WordPress plugin to the newest stable and safe version.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Ultimate Product Catalog [ultimate-product-catalogue] < 3.8.7

Because of this vulnerability, an attacker can upload arbitrary files to WordPress upload directory and manage this plugin with an especific account. Upgrade the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Ultimate Product Catalog [ultimate-product-catalogue] < 3.8.2

Ultimate Product Catalog plugin is prone to a privilege escalation vulnerability in the "<upc-plugin-path>/Functions/Update_Admin-Databases.php" file. It allows an attacker to manage the administration page and have an especific account. Upgrade the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Ultimate Product Catalog [ultimate-product-catalogue] < 3.8.2

The Ultimate Product Catalog plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the Update_UPCP_Options() function in versions up to, and including, 3.8.1. This makes it possible for authenticated attackers, with contributor-level permissions and above, to edit plugin settings.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3

The Ultimate Product Catalogue for WordPress is vulnerable to SQL Injection via the ‘Item_ID’ and 'SingleProduct' parameters in versions before 3.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3

Ultimate Product Catalogue plugin is prone to persistent cross-site scripting, cross-site request forgery and file upload vulnerabilities. Update the WordPress Ultimate Product Catalogue plugin to the latest version (at least 3.1.3)

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3

This WordPress Ultimate Product Catalogue plugin's "SingleProduct" parameter is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the WordPress Ultimate Product Catalogue plugin to the latest available version (at least version 3.1.3)

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.2

Remote unauthenticated attacker can exploit this issue by sending a specially-crafted HTTP POST request. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3

The Ultimate Product Catalog plugin for WordPress has multiple vulnerabilities in versions up to, and including, 3.1.2. This is due to a lack of sanitization of user input and insufficient checks on file types. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link, and for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.22

The Ultimate Product Catalog plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the Functions/Prepare_Data_For_Insertion.php file in versions up to, and including, 4.2.22. This makes it possible for unauthenticated attackers (before version 3.1.2) and authenticated attackers, with subscriber-level permissions and above (before version 4.2.22), to upload arbitrary files on the affected site's server which may make remote code execution possible.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Ultimate Product Catalog [ultimate-product-catalogue] < 2.1.1

The Ultimate Product Catalog plugin for WordPress is vulnerable to generic SQL Injection via the Catalogue_ID, SubCategory_ID, SingleProduct, & Tag_ID parameters in versions up to, and including, 2.1 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL queries. This makes it possible for authenticated attackers, with administrator-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Ultimate Product Catalog [ultimate-product-catalogue] < 4.2.3

Type user access: subscriber upwards. $_POST[‘CatID’] is not escaped. File / Code: Path: /wp-content/plugins/ultimate-product-catalogue/Functions/Process_Ajax.php

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Ultimate Product Catalog [ultimate-product-catalogue] < 3.9.9

The Ultimate Product Catalog – WordPress Catalog Plugin WordPress plugin was affected by an Unauthenticated Blind SQL Injection security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.5

Product Name and Description and File Upload formulary of plugin Ultimate Product Catalog lacks of proper CSRF protection and proper filtering. Allowing an attacker to alter a product presented to a customer or the wordpress administrators and insert XSS in his product name and description. It also allows an attacker to upload a php script though a CSRF due to a lack of file type filtering when uploading it.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.3

Unauthenticated SQL injection in parameter "SingleProduct" when a web visitor explores a product published by the web administrator. This exploit needs magic_quotes_gpc turned off in the destination server. File Functions/Shortcodes.php line 779

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Ultimate Product Catalog [ultimate-product-catalogue] < 3.1.2

By sending a specially-crafted HTTP POST request, a remote unauthenticated attacker can exploit this issue to upload arbitrary file and execute it in the context of the web server process.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Ultimate Product Catalogue actualizado — 5.3.15 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.