CVE-2020-36743
The Product Catalog Simple plugin versions 1.5.13 and earlier are susceptible to cross-site request forgery attacks because the implecode_save_products_meta() function does not properly validate nonces. An attacker could exploit this vulnerability by crafting a malicious request that, if clicked by an administrator, would allow the attacker to modify product metadata without proper authorization. Since nonce verification is absent or inadequate, unauthenticated users can perform these unauthorized actions.
Based on public CVE data (MITRE/NVD).