WP Sunshine Vulnerabilities and Affected Products
Vulnerabilities associated with Sunshine Photo Cart.
Products
Clear product- Sunshine Photo Cart4 vulnerabilities
- Sunshine Photo Cart: Free Client Galleries for Photographers1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-42776MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.6.7 - Broken Access Control vulnerabilityMissing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sunshine Photo Cart: from n/a through 3.6.7. CWE-862May 25, 2026 | CVSS6.3v3.1 | EPSS0.202% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-45826MEDIUM | WordPress Sunshine Photo Cart plugin <= 2.9.13 - Auth. Broken Access Control vulnerabilityMissing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 2.9.13. CWE-862Dec 13, 2024 | CVSS5.4v3.1 | EPSS0.413% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30221MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.1.1 - PHP Object Injection vulnerabilityDeserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1. CWE-502Mar 28, 2024 | CVSS5.4v3.1 | EPSS0.465% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-40692MEDIUM | WordPress Sunshine Photo Cart Plugin <= 2.9.13 is vulnerable to Cross Site Request Forgery (CSRF)Cross-Site Request Forgery (CSRF) vulnerability in WP Sunshine Sunshine Photo Cart plugin <= 2.9.13 versions. CWE-352Feb 2, 2023 | CVSS5.4v3.1 | EPSS0.264% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |