Description
Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.1.
Published: 2025-12-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Sunshine Photo Cart plugin for WordPress contains a missing authorization flaw that permits users to bypass intended access controls. Importantly, this is a broken access control issue identified as CWE-862. Attackers who can interact with the plugin could exploit the incorrect configuration of security levels to access or manipulate data or functionality that should be protected, potentially compromising confidentiality and integrity of photo cart content. While the vulnerability does not lead directly to remote code execution or denial of service, it does allow unauthorized operations within the plugin’s scope.

Affected Systems

Any WordPress installation that uses the Sunshine Photo Cart plugin, specifically versions from the earliest release through 3.5.7.1. The issue affects all customers who have not upgraded past this version threshold.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, primarily due to the access bypass, but leaves system integrity somewhat preserved. The EPSS score of <1% signals a very low likelihood of active exploitation. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited current exploitation. The attack surface is limited to users who can interact with the plugin, meaning that an attacker must either have a user account or be able to submit requests that reach the plugin’s endpoints. The overall risk is moderate, but remediation is still advisable to close the unauthorized access pathway.

Generated by OpenCVE AI on April 29, 2026 at 15:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Sunshine Photo Cart release that removes the broken access control flaw
  • If an immediate update is not possible, restrict the plugin’s scope to administrative or internal users only, reducing the exposure of privileged functions
  • Regularly monitor WordPress logs for anomalous access patterns to the plugin’s endpoints

Generated by OpenCVE AI on April 29, 2026 at 15:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Sunshinephotocart
Sunshinephotocart sunshine Photo Cart
Wordpress
Wordpress wordpress
Vendors & Products Sunshinephotocart
Sunshinephotocart sunshine Photo Cart
Wordpress
Wordpress wordpress

Wed, 24 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.1.
Title WordPress Sunshine Photo Cart plugin <= 3.5.7.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Sunshinephotocart Sunshine Photo Cart
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:29.918Z

Reserved: 2025-12-19T10:17:09.986Z

Link: CVE-2025-68535

cve-icon Vulnrichment

Updated: 2025-12-24T19:06:33.389Z

cve-icon NVD

Status : Deferred

Published: 2025-12-24T13:16:22.850

Modified: 2026-04-27T19:16:29.040

Link: CVE-2025-68535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T15:45:14Z

Weaknesses