Impact
The Sunshine Photo Cart WordPress plugin contains an access-control deficiency in an AJAX action that lets any internet user request the comments attached to images in galleries that are intended to be private, password-protected or otherwise restricted. Because no permission check is performed, the attacker can read all comments on those galleries, potentially exposing sensitive content or personal information. The flaw does not grant code execution or privilege escalation, but it compromises confidentiality of user-generated data and can be used to map out private galleries or gather information for social engineering attempts.
Affected Systems
All WordPress sites that have the Sunshine Photo Cart plugin installed with a version earlier than 3.6.12. None of the exact CPE strings are supplied, but the vendor/product is identified as Sunshine Photo Cart, a WordPress plugin. Site owners should audit installed plugins and verify that the Sunshine Photo Cart plugin is either absent or upgraded to version 3.6.12 or later.
Risk and Exploitability
The vulnerability’s CVSS score is 7.5, indicating a high severity, and its impact is clear: unauthenticated disclosure of private comments. Because the attacker only needs to send a normal HTTP request to a known AJAX endpoint, no special privileges or exploit code is required, which makes exploitation straightforward. The EPSS score is below 1% and the issue is not listed in the CISA KEV catalog, yet the low barrier to exploitation means the risk is significant for sites that rely on gallery privacy.
OpenCVE Enrichment