Impact
The vulnerability is a missing authorization flaw in the Sunshine Photo Cart WordPress plugin that allows attackers to bypass the intended access controls prescribed by role‑based permissions. An attacker could exploit specially crafted HTTP requests to access or modify plugin configuration and photo data that should only be reachable by privileged users.
Affected Systems
Sunshine Photo Cart plugin for WordPress versions up to and including 3.5.6.2.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity for this missing authorization weakness, which is classified as CWE‑862. The EPSS score of less than 1% shows a low observed probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. Nevertheless, an attacker could target the plugin’s endpoints, sending requests that are not adequately restricted by authentication checks. The flaw could be leveraged by authenticated users with insufficient roles or potentially by unauthenticated users if the plugin’s administrative pages are publicly accessible. The absence of an KEV listing does not lessen the practical risk for any WordPress installation that remains exposed to the Internet.
OpenCVE Enrichment