The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape settings values, leading to stored XSS by unauthenticated users.
https://wpscan.com/vulnerability/b37b09c1-1b53-471c-9b10-7d2d05ae11f1