CVE-2021-4393
The eCommerce Product Catalog Plugin for WordPress contains a Cross-Site Request Forgery vulnerability affecting versions 3.0.17 and earlier because the save() function fails to properly implement nonce verification. An attacker can exploit this flaw by crafting a malicious request that, if clicked by an administrator, allows unauthorized creation of manual digital orders on the affected site. The vulnerability requires social engineering to succeed but poses a significant risk to order integrity and site security.
Based on public CVE data (MITRE/NVD).