CVE · Medium

CVE-2025-62061 — Product Catalog Simple [post-type-x] < 1.8.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-62061 Product Catalog Simple [post-type-x] < 1.8.5 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.8.5 1.8.5 2025-10-16

CVE-2025-62061

The Product Catalog Simple plugin for WordPress contains a flaw in its security checks, allowing malicious individuals to execute unintended actions without proper authorization. Specifically, the vulnerability arises from inadequate verification of requests made by administrators, making it susceptible to exploitation via carefully crafted links or other tactics that manipulate site admins into taking specific actions inadvertently. This weakness affects all versions up to and including 1.8.4.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.