CVE-2025-62061
The Product Catalog Simple plugin for WordPress contains a flaw in its security checks, allowing malicious individuals to execute unintended actions without proper authorization. Specifically, the vulnerability arises from inadequate verification of requests made by administrators, making it susceptible to exploitation via carefully crafted links or other tactics that manipulate site admins into taking specific actions inadvertently. This weakness affects all versions up to and including 1.8.4.
Based on public CVE data (MITRE/NVD).