CVE · High

CVE-2025-49331 — eCommerce Product Catalog [ecommerce-product-catalog] < 3.4.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-49331 eCommerce Product Catalog [ecommerce-product-catalog] < 3.4.4 Deserialization of Untrusted Data High 7.2 < 3.4.4 3.4.4 2025-06-17

CVE-2025-49331

The eCommerce Product Catalog plugin for WordPress contains a flaw that allows attackers with elevated access to inject malicious PHP objects into the application's internal workings. This vulnerability affects versions up to 3.4.3 and can be exploited through the deserialization of untrusted input. If other plugins or themes on the affected site introduce a specific type of code execution chain, it may enable attackers to carry out damaging actions such as deleting files, accessing sensitive information, or running unauthorized code.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.