CVE-2025-49331
The eCommerce Product Catalog plugin for WordPress contains a flaw that allows attackers with elevated access to inject malicious PHP objects into the application's internal workings. This vulnerability affects versions up to 3.4.3 and can be exploited through the deserialization of untrusted input. If other plugins or themes on the affected site introduce a specific type of code execution chain, it may enable attackers to carry out damaging actions such as deleting files, accessing sensitive information, or running unauthorized code.
Based on public CVE data (MITRE/NVD).