PLUGIN SECURITY
Is eCommerce Product Catalog for WordPress safe?
eCommerce Product Catalog is a powerful and free plugin to sell with a beautiful eCommerce or request for a quote WordPress website.
What this plugin does
- Slug:
ecommerce-product-catalog - Author: impleCode
- 7000+ active installs
- 94/100 rating (269 reviews on wordpress.org)
- 1454360 all-time downloads
- On WordPress.org since 2014-01-27
catalogecommercequoterequest a quoteshopping cart
Maintenance status
- Latest known version: 3.5.7
- Last updated: 2026-08-24 3:01pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): <8.0
Known vulnerabilities
23 known CVEs on file for eCommerce Product Catalog for WordPress. Reported between 2020 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-57360 | eCommerce Product Catalog [ecommerce-product-catalog] < 3.5.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.5.5 | 3.5.5 | 2026-07-01 | ✓ fixed in latest |
| CVE-2026-76128 | eCommerce Product Catalog [ecommerce-product-catalog] < 3.5.11 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.5.11 | 3.5.11 | 2026-07-01 | ⚠ update needed |
| CVE-2026-52693 | eCommerce Product Catalog [ecommerce-product-catalog] < 3.5.6 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.3 | < 3.5.6 | 3.5.6 | 2026-06-09 | ✓ fixed in latest |
| CVE-2025-49331 | eCommerce Product Catalog [ecommerce-product-catalog] < 3.4.4 | Deserialization of Untrusted Data | High 7.2 | < 3.4.4 | 3.4.4 | 2025-06-17 | ✓ fixed in latest |
| CVE-2024-12771 | eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.44 | Cross-Site Request Forgery (CSRF) | High 8.8 | < 3.3.44 | 3.3.44 | 2024-12-20 | ✓ fixed in latest |
| CVE-2024-32558 | eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.33 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.3.33 | 3.3.33 | 2024-04-16 | ✓ fixed in latest |
| CVE-2024-32437 | eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.29 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 3.3.29 | 3.3.29 | 2024-04-12 | ✓ fixed in latest |
| CVE-2023-51688 | eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.27 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 3.3.27 | 3.3.27 | 2023-12-27 | ✓ fixed in latest |
+ 29 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-47839 | eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.27 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.3.27 | 3.3.27 | 2023-11-14 | ✓ fixed in latest |
| — | eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.26 | — | Unknown | < 3.3.26 | 3.3.26 | 2023-11-14 | ✓ fixed in latest |
| CVE-2023-5979 | eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.26 | Cross-Site Request Forgery (CSRF) | Medium 6.5 | < 3.3.26 | 3.3.26 | 2023-11-13 | ✓ fixed in latest |
| CVE-2021-4342 | eCommerce Product Catalog [ecommerce-product-catalog] < 2.9.44 | — | Unknown | < 2.9.44 | 2.9.44 | 2023-06-07 | ✓ fixed in latest |
| CVE-2023-1470 | eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 3.3.9 | 3.3.9 | 2023-03-17 | ✓ fixed in latest |
| CVE-2023-25049 | eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 3.3.5 | 3.3.5 | 2023-02-06 | ✓ fixed in latest |
| — | eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.72 | — | Unknown | < 3.0.72 | 3.0.72 | 2022-10-17 | ✓ fixed in latest |
| — | eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.72 | — | Unknown | < 3.0.72 | 3.0.72 | 2022-10-17 | ✓ fixed in latest |
| — | eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.71 | — | Unknown | < 3.0.71 | 3.0.71 | 2022-10-13 | ✓ fixed in latest |
| — | eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.70 | — | Unknown | < 3.0.70 | 3.0.70 | 2022-10-11 | ✓ fixed in latest |
| — | eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.71 | — | Unknown | < 3.0.71 | 3.0.71 | 2022-10-10 | ✓ fixed in latest |
| CVE-2021-24875 | eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.39 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.0.39 | 3.0.39 | 2021-10-25 | ✓ fixed in latest |
| CVE-2021-4392 | eCommerce Product Catalog [ecommerce-product-catalog] < 2.9.44 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 2.9.44 | 2.9.44 | 2021-03-21 | ✓ fixed in latest |
| CVE-2021-4393 | eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.18 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 3.0.18 | 3.0.18 | 2021-03-01 | ✓ fixed in latest |
| — | eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.18 | — | Unknown | < 3.0.18 | 3.0.18 | 2021-02-12 | ✓ fixed in latest |
| — | eCommerce Product Catalog [ecommerce-product-catalog] < 2.9.44 | — | Unknown | < 2.9.44 | 2.9.44 | 2020-09-16 | ✓ fixed in latest |
| — | eCommerce Product Catalog [ecommerce-product-catalog] < 2.9.44 | — | Unknown | < 2.9.44 | 2.9.44 | — | ✓ fixed in latest |
| — | eCommerce Product Catalog [ecommerce-product-catalog] < 2.9.44 | — | Unknown | < 2.9.44 | 2.9.44 | — | ✓ fixed in latest |
| — | eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.18 | — | Unknown | < 3.0.18 | 3.0.18 | — | ✓ fixed in latest |
| — | eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.72 | — | Unknown | < 3.0.72 | 3.0.72 | — | ✓ fixed in latest |
| — | eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.72 | — | Unknown | < 3.0.72 | 3.0.72 | — | ✓ fixed in latest |
| — | eCommerce Product Catalog [ecommerce-product-catalog] < 3.0.71 | — | Unknown | < 3.0.71 | 3.0.71 | — | ✓ fixed in latest |
| CVE-2020-36707, CVE-2021-4417, CVE-2020-36752, CVE-2020-36757, CVE-2020-36756, CVE-2020-36761, CVE-2020-36760, CVE-2020-36760 | Multiple Plugins/Themes - Cross-Site Request Forgery (CSRF) | — | Unknown | < 2.9.44 | 2.9.44 | — | ✓ fixed in latest |
| — | eCommerce Product Catalog < 3.0.18 - CSRF Nonce Bypass | — | Unknown | < 3.0.18 | 3.0.18 | — | ✓ fixed in latest |
| — | eCommerce Product Catalog Plugin for WordPress < 3.0.71 - Reflected XSS | — | Unknown | < 3.0.71 | 3.0.71 | — | ✓ fixed in latest |
| — | eCommerce Product Catalog Plugin for WordPress < 3.0.72 - Reflected XSS via AJAX | — | Unknown | < 3.0.72 | 3.0.72 | — | ✓ fixed in latest |
| — | eCommerce Product Catalog Plugin for WordPress < 3.0.72 - Reflected XSS | — | Unknown | < 3.0.72 | 3.0.72 | — | ✓ fixed in latest |
| CVE-2023-5979 | eCommerce Product Catalog Plugin for WordPress < 3.3.26 - Products Deletion via CSRF | — | Unknown | < 3.3.26 | 3.3.26 | — | ✓ fixed in latest |
| CVE-2023-47839 | eCommerce Product Catalog for WordPress < 3.3.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | — | Unknown | < 3.3.27 | 3.3.27 | — | ✓ fixed in latest |
How to fix it
Keep eCommerce Product Catalog for WordPress updated — 3.5.7 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WooCommerce — 7000000+ active installs — 90/100 (4819)
- Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation — 1000000+ active installs — 86/100 (815) — max PHP 8.4
- WooCommerce PayPal Payments — 800000+ active installs — 56/100 (577) — max PHP 8.4
- Mailchimp for WooCommerce — 200000+ active installs — 80/100 (725) — max PHP 8.4
- WPML Multilingual & Multicurrency for WooCommerce — 100000+ active installs — 84/100 (453)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.