PLUGIN SECURITY

Is eCommerce Product Catalog for WordPress safe?

eCommerce Product Catalog is a powerful and free plugin to sell with a beautiful eCommerce or request for a quote WordPress website.

What this plugin does

  • Slug: ecommerce-product-catalog
  • Author: impleCode
  • 7000+ active installs
  • 94/100 rating (269 reviews on wordpress.org)
  • 1454360 all-time downloads
  • On WordPress.org since 2014-01-27

catalogecommercequoterequest a quoteshopping cart

Maintenance status

  • Latest known version: 3.5.7
  • Last updated: 2026-08-24 3:01pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): <8.0

Known vulnerabilities

23 known CVEs on file for eCommerce Product Catalog for WordPress. Reported between 2020 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-57360 eCommerce Product Catalog [ecommerce-product-catalog] < 3.5.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.5.5 3.5.5 2026-07-01 ✓ fixed in latest
CVE-2026-76128 eCommerce Product Catalog [ecommerce-product-catalog] < 3.5.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.5.11 3.5.11 2026-07-01 ⚠ update needed
CVE-2026-52693 eCommerce Product Catalog [ecommerce-product-catalog] < 3.5.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.3 < 3.5.6 3.5.6 2026-06-09 ✓ fixed in latest
CVE-2025-49331 eCommerce Product Catalog [ecommerce-product-catalog] < 3.4.4 Deserialization of Untrusted Data High 7.2 < 3.4.4 3.4.4 2025-06-17 ✓ fixed in latest
CVE-2024-12771 eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.44 Cross-Site Request Forgery (CSRF) High 8.8 < 3.3.44 3.3.44 2024-12-20 ✓ fixed in latest
CVE-2024-32558 eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.33 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.3.33 3.3.33 2024-04-16 ✓ fixed in latest
CVE-2024-32437 eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.29 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.3.29 3.3.29 2024-04-12 ✓ fixed in latest
CVE-2023-51688 eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.27 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 3.3.27 3.3.27 2023-12-27 ✓ fixed in latest
+ 29 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-47839 eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.27 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.3.27 3.3.27 2023-11-14 ✓ fixed in latest
eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.26 Unknown < 3.3.26 3.3.26 2023-11-14 ✓ fixed in latest
CVE-2023-5979 eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.26 Cross-Site Request Forgery (CSRF) Medium 6.5 < 3.3.26 3.3.26 2023-11-13 ✓ fixed in latest
CVE-2021-4342 eCommerce Product Catalog [ecommerce-product-catalog] < 2.9.44 Unknown < 2.9.44 2.9.44 2023-06-07 ✓ fixed in latest
CVE-2023-1470 eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.3.9 3.3.9 2023-03-17 ✓ fixed in latest
CVE-2023-25049 eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 3.3.5 3.3.5 2023-02-06 ✓ fixed in latest
eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.72 Unknown < 3.0.72 3.0.72 2022-10-17 ✓ fixed in latest
eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.72 Unknown < 3.0.72 3.0.72 2022-10-17 ✓ fixed in latest
eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.71 Unknown < 3.0.71 3.0.71 2022-10-13 ✓ fixed in latest
eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.70 Unknown < 3.0.70 3.0.70 2022-10-11 ✓ fixed in latest
eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.71 Unknown < 3.0.71 3.0.71 2022-10-10 ✓ fixed in latest
CVE-2021-24875 eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.39 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.0.39 3.0.39 2021-10-25 ✓ fixed in latest
CVE-2021-4392 eCommerce Product Catalog [ecommerce-product-catalog] < 2.9.44 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.9.44 2.9.44 2021-03-21 ✓ fixed in latest
CVE-2021-4393 eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.18 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.0.18 3.0.18 2021-03-01 ✓ fixed in latest
eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.18 Unknown < 3.0.18 3.0.18 2021-02-12 ✓ fixed in latest
eCommerce Product Catalog [ecommerce-product-catalog] < 2.9.44 Unknown < 2.9.44 2.9.44 2020-09-16 ✓ fixed in latest
eCommerce Product Catalog [ecommerce-product-catalog] < 2.9.44 Unknown < 2.9.44 2.9.44 ✓ fixed in latest
eCommerce Product Catalog [ecommerce-product-catalog] < 2.9.44 Unknown < 2.9.44 2.9.44 ✓ fixed in latest
eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.18 Unknown < 3.0.18 3.0.18 ✓ fixed in latest
eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.72 Unknown < 3.0.72 3.0.72 ✓ fixed in latest
eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.72 Unknown < 3.0.72 3.0.72 ✓ fixed in latest
eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.71 Unknown < 3.0.71 3.0.71 ✓ fixed in latest
CVE-2020-36707, CVE-2021-4417, CVE-2020-36752, CVE-2020-36757, CVE-2020-36756, CVE-2020-36761, CVE-2020-36760, CVE-2020-36760 Multiple Plugins/Themes - Cross-Site Request Forgery (CSRF) Unknown < 2.9.44 2.9.44 ✓ fixed in latest
eCommerce Product Catalog < 3.0.18 - CSRF Nonce Bypass Unknown < 3.0.18 3.0.18 ✓ fixed in latest
eCommerce Product Catalog Plugin for WordPress < 3.0.71 - Reflected XSS Unknown < 3.0.71 3.0.71 ✓ fixed in latest
eCommerce Product Catalog Plugin for WordPress < 3.0.72 - Reflected XSS via AJAX Unknown < 3.0.72 3.0.72 ✓ fixed in latest
eCommerce Product Catalog Plugin for WordPress < 3.0.72 - Reflected XSS Unknown < 3.0.72 3.0.72 ✓ fixed in latest
CVE-2023-5979 eCommerce Product Catalog Plugin for WordPress < 3.3.26 - Products Deletion via CSRF Unknown < 3.3.26 3.3.26 ✓ fixed in latest
CVE-2023-47839 eCommerce Product Catalog for WordPress < 3.3.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Unknown < 3.3.27 3.3.27 ✓ fixed in latest

How to fix it

Keep eCommerce Product Catalog for WordPress updated — 3.5.7 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.