PLUGIN SECURITY
Is Product Catalog Simple safe?
Catalog plugin with fully customizable responsive design, search and categories. Best for product catalog and services or portfolio presentation.
What this plugin does
- Slug:
post-type-x - Author: impleCode
- 1000+ active installs
- 90/100 rating (13 reviews on wordpress.org)
- 83022 all-time downloads
- On WordPress.org since 2015-10-08
catalogcatalogueproductproduct catalogproduct gallery
Maintenance status
- Latest known version: 1.8.6
- Last updated: 2026-08-21 9:05am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
15 known CVEs on file for Product Catalog Simple.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-62061 | Product Catalog Simple [post-type-x] < 1.8.5 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 1.8.5 | 1.8.5 | 2025-10-16 | ✓ fixed in latest |
| CVE-2025-49305 | Product Catalog Simple [post-type-x] < 1.8.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 1.8.2 | 1.8.2 | 2025-06-05 | ✓ fixed in latest |
| CVE-2023-51687 | Product Catalog Simple [post-type-x] < 1.7.7 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 1.7.7 | 1.7.7 | 2023-12-27 | ✓ fixed in latest |
| — | Product Catalog Simple [post-type-x] < 1.7.6 | — | Unknown | < 1.7.6 | 1.7.6 | 2023-11-09 | ✓ fixed in latest |
| — | Product Catalog Simple [post-type-x] < 1.7.6 | — | Unknown | < 1.7.6 | 1.7.6 | 2023-11-08 | ✓ fixed in latest |
| CVE-2021-4342 | Product Catalog Simple [post-type-x] < 1.5.13 | — | Unknown | < 1.5.13 | 1.5.13 | 2023-06-07 | ✓ fixed in latest |
| CVE-2023-29388 | Product Catalog Simple [post-type-x] < 1.7.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 1.7.0 | 1.7.0 | 2023-04-06 | ✓ fixed in latest |
| — | Product Catalog Simple [post-type-x] < 1.5.13 | — | Unknown | < 1.5.13 | 1.5.13 | 2020-09-16 | ✓ fixed in latest |
+ 10 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2020-36743 | Product Catalog Simple [post-type-x] < 1.5.13 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 1.5.13 | 1.5.13 | 2020-09-16 | ✓ fixed in latest |
| — | Product Catalog Simple [post-type-x] < 1.8.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 1.8.0 | 1.8.0 | 0000-00-00 | ✓ fixed in latest |
| — | Product Catalog Simple [post-type-x] < 1.8.3 | — | Medium 6.5 | < 1.8.3 | 1.8.3 | 0000-00-00 | ✓ fixed in latest |
| — | Product Catalog Simple [post-type-x] < 1.5.13 | — | Unknown | < 1.5.13 | 1.5.13 | — | ✓ fixed in latest |
| — | Product Catalog Simple [post-type-x] < 1.5.13 | — | Unknown | < 1.5.13 | 1.5.13 | — | ✓ fixed in latest |
| — | Product Catalog Simple [post-type-x] < 1.7.6 | — | Unknown | < 1.7.6 | 1.7.6 | — | ✓ fixed in latest |
| CVE-2020-36707, CVE-2021-4417, CVE-2020-36752, CVE-2020-36757, CVE-2020-36756, CVE-2020-36761, CVE-2020-36760, CVE-2020-36760 | Multiple Plugins/Themes - Cross-Site Request Forgery (CSRF) | — | Unknown | < 1.5.13 | 1.5.13 | — | ✓ fixed in latest |
| — | Product Catalog Simple < 1.7.6 - Cross-Site Request Forgery via ic_system_status | — | Unknown | < 1.7.6 | 1.7.6 | — | ✓ fixed in latest |
| CVE-2025-1405 | Product Catalog Simple < 1.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via show_products Shortcode | — | Unknown | < 1.8.0 | 1.8.0 | — | ✓ fixed in latest |
| CVE-2025-58992 | Product Catalog Simple < 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | Unknown | < 1.8.3 | 1.8.3 | — | ✓ fixed in latest |
How to fix it
Keep Product Catalog Simple updated — 1.8.6 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- eCommerce Product Catalog — 7000+ active installs — 94/100 (269) — max PHP <8.0
- Ultimate Product Catalog — 4000+ active installs — 90/100 (233) — max PHP 8.4
- OnSale Page for WooCommerce — 2000+ active installs — 90/100 (26) — max PHP 8.4
- External Store for Shopify — 2000+ active installs — 68/100 (5) — max PHP 8.4
- FlippingBook — 2000+ active installs — 80/100 (4)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.