plugin

Sunshine Photo Cart Vulnerabilities

51 known security issues reported for the Sunshine Photo Cart WordPress plugin. Most recent disclosed Jul 27, 2026.

2 critical 2 high 20 medium

Running Sunshine Photo Cart on your site? Check whether your installed version is affected.

Scan your site free

Sunshine Photo Cart <= 3.6.11 - Missing Authorization

medium

The Sunshine Photo Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.6.11. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.6.11
Fixed in:
3.6.12
Disclosed:
Jul 27, 2026

CVE-2026-16561 on NVD →

Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers <= 3.6.10.1 - Missing Authorization

medium

The Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.6.10.1. This makes it possible for authenticated attackers, with subscriber-level access and abo...

CVSS:
4.3
Affected:
up to 3.6.10.1
Fixed in:
3.6.11
Disclosed:
Jul 20, 2026

CVE-2026-57703 on NVD →

Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers <= 3.6.7 - Missing Authorization

medium

The Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with subscriber-level access and above,...

CVSS:
4.3
Affected:
up to 3.6.7
Fixed in:
3.6.8
Disclosed:
May 26, 2026

CVE-2026-42776 on NVD →

Sunshine Photo Cart < 3.6.2 - Unauthenticated Information Exposure

medium

The Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 3.6.2 (exclusive). This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 3.6.2
Fixed in:
3.6.2
Disclosed:
Mar 26, 2026

CVE-2026-39564 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] <= 3.5.6.2 (unfixed)

unknown

[en] Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.6.2.

Affected:
up to 3.5.6.2
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2025-67973 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] <= 3.5.7.2 (unfixed)

unknown

[en] Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.2.

Affected:
up to 3.5.7.2
Fix:
No patched version reported
Disclosed:
Feb 3, 2026

CVE-2026-24994 on NVD →

Sunshine Photo Cart <= 3.5.6.2 - Missing Authorization

medium

The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.6.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.5.6.2
Fixed in:
3.5.7.1
Disclosed:
Jan 27, 2026

CVE-2025-67973 on NVD →

Sunshine Photo Cart <= 3.5.7.2 - Missing Authorization

medium

The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.7.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.5.7.2
Fixed in:
3.5.7.3
Disclosed:
Jan 23, 2026

CVE-2026-24994 on NVD →

Sunshine Photo Cart <= 3.5.7.1 - Missing Authorization

medium

The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.7.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to p...

CVSS:
4.3
Affected:
up to 3.5.7.1
Fixed in:
3.5.7.2
Disclosed:
Dec 30, 2025

CVE-2025-68535 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] <= 3.5.7.1 (unfixed)

unknown

[en] Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.1.

Affected:
up to 3.5.7.1
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68535 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] <= 3.5.3 (unfixed)

unknown

[en] Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.3.

Affected:
up to 3.5.3
Fix:
No patched version reported
Disclosed:
Oct 27, 2025

CVE-2025-62892 on NVD →

Sunshine Photo Cart <= 3.5.3 - Missing Authorization

medium

The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.5.3
Fixed in:
3.5.4
Disclosed:
Aug 29, 2025

CVE-2025-62892 on NVD →

Sunshine Photo Cart <= 3.4.11 - Authenticated (Subscriber+) Privilege Escalation

high

The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.11. This is due to the plugin not properly validating a user-supplied key. This makes it possible for authenticated attackers,...

CVSS:
8.8
Affected:
up to 3.4.11
Fixed in:
3.4.12
Disclosed:
Jun 3, 2025

CVE-2025-5482 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 3.4.11

unknown

[en] Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart allows Object Injection. This issue affects Sunshine Photo Cart: from n/a through 3.4.10.

Affected:
up to 3.4.11
Fixed in:
3.4.11
Disclosed:
Apr 1, 2025

CVE-2025-31084 on NVD →

Sunshine Photo Cart <= 3.4.10 - Unauthenticated PHP Object Injection

critical

The Sunshine Photo Cart plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.4.10 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is pre...

CVSS:
9.8
Affected:
up to 3.4.10
Fixed in:
3.4.11
Disclosed:
Mar 28, 2025

CVE-2025-31084 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 2.9.14

unknown

[en] Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 2.9.13.

Affected:
up to 2.9.14
Fixed in:
2.9.14
Disclosed:
Dec 13, 2024

CVE-2022-45826 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 3.2.10

unknown

[en] Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 3.2.9.

Affected:
up to 3.2.10
Fixed in:
3.2.10
Disclosed:
Nov 19, 2024

CVE-2024-49697 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 3.2.9

unknown

[en] Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 3.2.8.

Affected:
up to 3.2.9
Fixed in:
3.2.9
Disclosed:
Nov 1, 2024

CVE-2024-47314 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 3.2.10

unknown

[en] Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 3.2.9.

Affected:
up to 3.2.10
Fixed in:
3.2.10
Disclosed:
Nov 1, 2024

CVE-2024-44038 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 3.2.2

unknown

[en] Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 3.2.1.

Affected:
up to 3.2.2
Fixed in:
3.2.2
Disclosed:
Nov 1, 2024

CVE-2024-43136 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 3.2.11

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP Sunshine Sunshine Photo Cart.This issue affects Sunshine Photo Cart: from n/a through 3.2.9.

Affected:
up to 3.2.11
Fixed in:
3.2.11
Disclosed:
Oct 28, 2024

CVE-2024-50463 on NVD →

Sunshine Photo Cart <= 3.2.9 - Open Redirect

medium

The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.2.9. This is due to insufficient validation on a redirect url. This makes it possible for unauthenticated attackers to redirect users to potentially maliciou...

CVSS:
6.1
Affected:
up to 3.2.9
Fixed in:
3.2.11
Disclosed:
Oct 24, 2024

CVE-2024-50463 on NVD →

Sunshine Photo Cart <= 3.2.9 - Missing Authorization

medium

The Sunshine Photo Cart plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the search_galleries() function in versions up to, and including, 3.2.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to search galleries.

CVSS:
4.3
Affected:
up to 3.2.9
Fixed in:
3.2.10
Disclosed:
Oct 21, 2024

CVE-2024-49697 on NVD →

Sunshine Photo Cart <= 3.2.8 - Missing Authorization

medium

The Sunshine Photo Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sunshine_addon_toggle() function in versions up to, and including, 3.2.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to toggle addons on and off.

CVSS:
4.3
Affected:
up to 3.2.8
Fixed in:
3.2.9
Disclosed:
Sep 25, 2024

CVE-2024-47314 on NVD →

Sunshine Photo Cart <= 3.2.9 - Missing Authorization

medium

The Sunshine Photo Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to perform unauthorized actions.

CVSS:
5.3
Affected:
up to 3.2.9
Fixed in:
3.2.10
Disclosed:
Sep 23, 2024

CVE-2024-44038 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 3.2.6

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Sunshine Sunshine Photo Cart allows Reflected XSS.This issue affects Sunshine Photo Cart: from n/a through 3.2.5.

Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Sep 17, 2024

CVE-2024-43971 on NVD →

Sunshine Photo Cart <= 3.2.5 - Reflected Cross-Site Scripting

medium

The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

CVSS:
6.1
Affected:
up to 3.2.5
Fixed in:
3.2.6
Disclosed:
Aug 28, 2024

CVE-2024-43971 on NVD →

Sunshine Photo Cart <= 3.2.1 - Missing Authorization

medium

The Sunshine Photo Cart plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sunshine_add_to_favorites() function in versions up to, and including, 3.2.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to favorite i...

CVSS:
4.3
Affected:
up to 3.2.1
Fixed in:
3.2.2
Disclosed:
Aug 7, 2024

CVE-2024-43136 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 3.1.2

unknown

[en] Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart.This issue affects Sunshine Photo Cart: from n/a through 3.1.1.

Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Mar 28, 2024

CVE-2024-30221 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 3.1.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Sunshine Sunshine Photo Cart allows Reflected XSS.This issue affects Sunshine Photo Cart: from n/a through 3.1.1.

Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Mar 27, 2024

CVE-2024-30194 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers <= 3.1.1 - Unauthenticated PHP Object Injection

critical

The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present...

CVSS:
9.8
Affected:
up to 3.1.1
Fixed in:
3.1.2
Disclosed:
Mar 26, 2024

CVE-2024-30221 on NVD →

Sunshine Photo Cart <= 3.1.1 - Reflected Cross-Site Scripting

medium

The Sunshine Photo Cart plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...

CVSS:
6.1
Affected:
up to 3.1.1
Fixed in:
3.1.2
Disclosed:
Mar 25, 2024

CVE-2024-30194 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 3.1

unknown

[en] The Sunshine Photo Cart: Free Client Galleries for Photographers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.24 via the 'invoice'. This makes it possible for unauthenticated attackers to extract sensitive data including customer email and physical...

Affected:
up to 3.1
Fixed in:
3.1
Disclosed:
Feb 20, 2024

CVE-2024-1294 on NVD →

Sunshine Photo Cart: Free Client Galleries for Photographers <= 3.0.24 - Unauthenticated Sensitive Information Exposure via Invoice

medium

The Sunshine Photo Cart: Free Client Galleries for Photographers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.24 via the 'invoice'. This makes it possible for unauthenticated attackers to extract sensitive data including customer email and physical addre...

CVSS:
5.3
Affected:
up to 3.0.24
Fixed in:
3.1
Disclosed:
Feb 12, 2024

CVE-2024-1294 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 3.0.0

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in WP Sunshine Sunshine Photo Cart: Free Client Galleries for Photographers.This issue affects Sunshine Photo Cart: Free Client Galleries for Photographers: from n/a before 3.0.0.

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Dec 20, 2023

CVE-2023-41796 on NVD →

Sunshine Photo Cart <= 2.9.25 - Insecure Direct Object Reference to Order Manipulation

medium

The Sunshine Photo Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.9.25 due to missing validation on a user-controlled key. This can allow unauthenticated attackers to manipulate orders that do not belong to them.

CVSS:
5.3
Affected:
up to 2.9.25
Fixed in:
3.0
Disclosed:
Sep 5, 2023

CVE-2023-41796 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 2.8.29

unknown

[en] The Sunshine Photo Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.28 This is due to missing or incorrect nonce validation on the sunshine_products_quicksave_post() function. This makes it possible for unauthenticated attackers to save custom post data vi...

Affected:
up to 2.8.29
Fixed in:
2.8.29
Disclosed:
Jul 12, 2023

CVE-2021-4415 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 2.8.29

unknown
Affected:
up to 2.8.29
Fixed in:
2.8.29
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 2.9.15

unknown
Affected:
up to 2.9.15
Fixed in:
2.9.15
Disclosed:
Apr 12, 2023

CVE-2022-4463 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 2.9.14

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WP Sunshine Sunshine Photo Cart plugin <= 2.9.13 versions.

Affected:
up to 2.9.14
Fixed in:
2.9.14
Disclosed:
Feb 2, 2023

CVE-2022-40692 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 2.9.15

unknown

[en] The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

Affected:
up to 2.9.15
Fixed in:
2.9.15
Disclosed:
Jan 9, 2023

CVE-2022-4301 on NVD →

Sunshine Photo Cart <= 2.9.14 - Reflected Cross-Site Scripting

medium

The Sunshine Photo Cart plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter in versions up to, and including, 2.9.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 2.9.14
Fixed in:
2.9.15
Disclosed:
Dec 12, 2022

CVE-2022-4301 on NVD →

Sunshine Photo Cart <= 2.9.13 - Cross-Site Request Forgery

high

The Sunshine Photo Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.13. This is due to missing or incorrect nonce validation on the sunshine_update_image_location_ajax function. This makes it possible for unauthenticated attackers to change image file paths, vi...

CVSS:
8.8
Affected:
up to 2.9.13
Fixed in:
2.9.14
Disclosed:
Dec 2, 2022

CVE-2022-40692 on NVD →

Sunshine Photo Cart <= 2.9.13 - Missing Authorization

medium

The Sunshine Photo Cart plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the sunshine_update_image_location_ajax function in versions up to, and including, 2.9.13. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change im...

CVSS:
6.3
Affected:
up to 2.9.13
Fixed in:
2.9.14
Disclosed:
Dec 2, 2022

CVE-2022-45826 on NVD →

Sunshine Photo Cart <= 2.8.28 - Cross-Site Request Forgery Bypass

medium

The Sunshine Photo Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.28 This is due to missing or incorrect nonce validation on the sunshine_products_quicksave_post() function. This makes it possible for unauthenticated attackers to save custom post data via a f...

CVSS:
4.3
Affected:
up to 2.8.28
Fixed in:
2.8.29
Disclosed:
Jun 21, 2021

CVE-2021-4415 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 2.8.29

unknown

Cross-Site Request Forgery (CSRF) vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Sunshine Photo Cart plugin (versions <= 2.8.28).

Affected:
up to 2.8.29
Fixed in:
2.8.29
Disclosed:
Jun 21, 2021

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 3.4.12

unknown
Affected:
up to 3.4.12
Fixed in:
3.4.12

CVE-2025-5482 on NVD →

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 2.8.29

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 2.8.29
Fixed in:
2.8.29

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 2.8.29

unknown

Multiple plugins are affected by CSRF bypass as they do not properly check for the nonce due to a logic flaw. This could allow attackers to make logged in users do unwanted actions

Affected:
up to 2.8.29
Fixed in:
2.8.29

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 2.9.14

unknown

Update the WordPress Sunshine Photo Cart plugin to the latest available version (at least 2.9.14). Lana Codes discovered and reported this Broken Access Control vulnerability in WordPress Sunshine Photo Cart Plugin. This vulnerability has been fixed in version 2.9.14.

Affected:
up to 2.9.14
Fixed in:
2.9.14

Sunshine Photo Cart: Free Client Photo Galleries for Photographers [sunshine-photo-cart] < 2.9.14

unknown

Update the WordPress Sunshine Photo Cart plugin to the latest available version (at least 2.9.14). Lana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Sunshine Photo Cart Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted acti...

Affected:
up to 2.9.14
Fixed in:
2.9.14

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database