sunshinephotocart Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with sunshinephotocart products.
Products
- Sunshine Photo Cart15 vulnerabilities
- sunshine_photo_cart4 vulnerabilities
- Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-57703MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.6.10.1 - Broken Access Control vulnerabilitySubscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions. CWE-862Jul 23, 2026 | CVSS6.3v3.1 | EPSS0.249% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-39564MEDIUM | WordPress Sunshine Photo Cart plugin < 3.6.2 - Sensitive Data Exposure vulnerabilityInsertion of Sensitive Information Into Sent Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Retrieve Embedded Sensitive Data.This issue affects Sunshine Photo Cart: from n/a through < 3.6.2. CWE-201Apr 8, 2026 | CVSS5.3v3.1 | EPSS0.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67973MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.5.6.2 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.6.2. CWE-862Feb 20, 2026 | CVSS6.5v3.1 | EPSS0.235% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24994MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.5.7.2 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.2. CWE-862Feb 3, 2026 | CVSS5.3v3.1 | EPSS0.187% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-68535MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.5.7.1 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.1. CWE-862Dec 24, 2025 | CVSS4.3v3.1 | EPSS0.169% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62892MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.5.3 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.3. CWE-862Oct 27, 2025 | CVSS5.3v3.1 | EPSS0.254% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-5482HIGH | Sunshine Photo Cart <= 3.4.11 - Authenticated (Subscriber+) Privilege EscalationThe Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.11. This is due to the plugin not properly validating a user-supplied key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary user's passwords through the password reset functionality, including administrators, and leverage that to reset the user… CWE-620Jun 4, 2025 | CVSS8.8v3.1 | EPSS0.496% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-31084CRITICAL | WordPress Sunshine Photo Cart plugin <= 3.4.10 - PHP Object Injection VulnerabilityDeserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through <= 3.4.10. CWE-502Apr 1, 2025 | CVSS9.8v3.1 | EPSS0.675% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49697MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.2.9 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9. CWE-862Nov 19, 2024 | CVSS4.3v3.1 | EPSS0.404% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-47314HIGH | WordPress Sunshine Photo Cart plugin <= 3.2.8 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.8. CWE-862Nov 1, 2024 | CVSS7.1v3.1 | EPSS0.396% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-44038MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.2.9 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9. CWE-862Nov 1, 2024 | CVSS5.3v3.1 | EPSS0.412% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43136MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.2.1 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.1. CWE-862Nov 1, 2024 | CVSS4.3v3.1 | EPSS0.439% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-50463MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.2.9 - Open Redirection vulnerabilityURL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9. CWE-601Oct 28, 2024 | CVSS4.7v3.1 | EPSS0.258% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43971HIGH | WordPress Sunshine Photo Cart plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.5. | CVSS7.1v3.1 | EPSS0.593% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-30221MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.1.1 - PHP Object Injection vulnerabilityDeserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1. CWE-502Mar 28, 2024 | CVSS5.4v3.1 | EPSS0.465% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30194HIGH | WordPress Sunshine Photo Cart plugin <= 3.1.1 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1. | CVSS7.1v3.1 | EPSS0.721% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-1294MEDIUM | Sunshine Photo Cart: Free Client Galleries for Photographers <= 3.0.24 - Unauthenticated Sensitive Information Exposure via InvoiceThe Sunshine Photo Cart: Free Client Galleries for Photographers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.24 via the 'invoice'. This makes it possible for unauthenticated attackers to extract sensitive data including customer email and physical addresses. CWE-284Feb 20, 2024 | CVSS5.3v3.1 | EPSS0.678% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-4415MEDIUM | Sunshine Photo Cart <= 2.8.28 - Cross-Site Request Forgery BypassThe Sunshine Photo Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.28 This is due to missing or incorrect nonce validation on the sunshine_products_quicksave_post() function. This makes it possible for unauthenticated attackers to save custom post data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CWE-352Jul 12, 2023 | CVSS4.3v3.1 | EPSS0.388% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |