sunshinephotocart Vulnerabilities and Affected Products
Vulnerabilities associated with Sunshine Photo Cart.
Products
Clear product- Sunshine Photo Cart15 vulnerabilities
- sunshine_photo_cart4 vulnerabilities
- Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-57703MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.6.10.1 - Broken Access Control vulnerabilitySubscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions. CWE-862Jul 23, 2026 | CVSS6.3v3.1 | EPSS0.249% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-39564MEDIUM | WordPress Sunshine Photo Cart plugin < 3.6.2 - Sensitive Data Exposure vulnerabilityInsertion of Sensitive Information Into Sent Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Retrieve Embedded Sensitive Data.This issue affects Sunshine Photo Cart: from n/a through < 3.6.2. CWE-201Apr 8, 2026 | CVSS5.3v3.1 | EPSS0.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67973MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.5.6.2 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.6.2. CWE-862Feb 20, 2026 | CVSS6.5v3.1 | EPSS0.235% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24994MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.5.7.2 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.2. CWE-862Feb 3, 2026 | CVSS5.3v3.1 | EPSS0.187% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-68535MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.5.7.1 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.1. CWE-862Dec 24, 2025 | CVSS4.3v3.1 | EPSS0.169% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62892MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.5.3 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.3. CWE-862Oct 27, 2025 | CVSS5.3v3.1 | EPSS0.254% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-31084CRITICAL | WordPress Sunshine Photo Cart plugin <= 3.4.10 - PHP Object Injection VulnerabilityDeserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through <= 3.4.10. CWE-502Apr 1, 2025 | CVSS9.8v3.1 | EPSS0.675% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49697MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.2.9 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9. CWE-862Nov 19, 2024 | CVSS4.3v3.1 | EPSS0.404% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-47314HIGH | WordPress Sunshine Photo Cart plugin <= 3.2.8 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.8. CWE-862Nov 1, 2024 | CVSS7.1v3.1 | EPSS0.396% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-44038MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.2.9 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9. CWE-862Nov 1, 2024 | CVSS5.3v3.1 | EPSS0.412% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43136MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.2.1 - Broken Access Control vulnerabilityMissing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.1. CWE-862Nov 1, 2024 | CVSS4.3v3.1 | EPSS0.439% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-50463MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.2.9 - Open Redirection vulnerabilityURL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9. CWE-601Oct 28, 2024 | CVSS4.7v3.1 | EPSS0.258% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43971HIGH | WordPress Sunshine Photo Cart plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.5. | CVSS7.1v3.1 | EPSS0.593% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-30221MEDIUM | WordPress Sunshine Photo Cart plugin <= 3.1.1 - PHP Object Injection vulnerabilityDeserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1. CWE-502Mar 28, 2024 | CVSS5.4v3.1 | EPSS0.465% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30194HIGH | WordPress Sunshine Photo Cart plugin <= 3.1.1 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1. | CVSS7.1v3.1 | EPSS0.721% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |