WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Ultimate Product Catalog

Add a product catalog to your site with blocks or shortcodes. Works with WooCommerce or standalone. Flexible and customizable, works with any theme.

9Reported vulnerabilities
9.8Highest CVSS score
5.3.16Latest version
4,000+Active installs

What to do now

Update Ultimate Product Catalog to 5.0.0 or later. 9 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 29, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
WF-21930a4f-2f78-42c5-8ffa-2993333db2fe Critical 9.8 Before 3.1.3 3.1.3 June 7, 2015
WF-a30863c5-2e94-4952-b360-856394262023 Critical 9.8 Before 4.2.22 4.2.22 April 22, 2015
CVE-2016-20075 High 8.8 0.3% 4.4.48 and earlier 5.0.0 June 15, 2026
WF-edcc23e0-075a-47e6-979d-7e75eed4337d High 8.8 4.2.21 and earlier 4.2.22 October 3, 2017
WF-0f2e39b3-c18c-4660-b23d-00790156bc7f High 8.8 Before 3.1.3 3.1.3 April 22, 2015
WF-1419f089-7656-43a1-aeee-c33eef604c84 High 7.2 2.1 and earlier 2.1.1 May 28, 2014
WF-cb4e3b3c-20f4-4591-af0a-539b405d675e Medium 5.4 Before 4.2.3 4.2.3 June 27, 2017
CVE-2024-31921 Medium 4.3 0.2% 5.2.15 and earlier 5.2.16 April 10, 2024
WF-2cff84a4-9264-4789-997b-bc11a8bac449 Medium 4.3 Before 3.8.2 3.8.2 June 17, 2016

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.