Description
The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Sunshine Photo Cart WordPress plugin contains an access-control deficiency in an AJAX action that lets any internet user request the comments attached to images in galleries that are intended to be private, password-protected or otherwise restricted. Because no permission check is performed, the attacker can read all comments on those galleries, potentially exposing sensitive content or personal information. The flaw does not grant code execution or privilege escalation, but it compromises confidentiality of user-generated data and can be used to map out private galleries or gather information for social engineering attempts.

Affected Systems

All WordPress sites that have the Sunshine Photo Cart plugin installed with a version earlier than 3.6.12. None of the exact CPE strings are supplied, but the vendor/product is identified as Sunshine Photo Cart, a WordPress plugin. Site owners should audit installed plugins and verify that the Sunshine Photo Cart plugin is either absent or upgraded to version 3.6.12 or later.

Risk and Exploitability

The vulnerability’s CVSS score is 7.5, indicating a high severity, and its impact is clear: unauthenticated disclosure of private comments. Because the attacker only needs to send a normal HTTP request to a known AJAX endpoint, no special privileges or exploit code is required, which makes exploitation straightforward. The EPSS score is below 1% and the issue is not listed in the CISA KEV catalog, yet the low barrier to exploitation means the risk is significant for sites that rely on gallery privacy.

Generated by OpenCVE AI on August 5, 2026 at 19:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Sunshine Photo Cart plugin to version 3.6.12 or newer to include the missing access-control check.
  • If an immediate upgrade cannot be performed, block unauthenticated requests to the vulnerable AJAX endpoint—e.g., add a server-side rule that returns a 403 status for anonymous users.
  • After the fix or workaround, review the site for comments that may have been exposed and take appropriate action to delete or anonymize them.

Generated by OpenCVE AI on August 5, 2026 at 19:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 05 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.
Title Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-05T14:51:36.628Z

Reserved: 2026-07-22T12:12:33.078Z

Link: CVE-2026-16561

cve-icon Vulnrichment

Updated: 2026-08-05T14:51:01.353Z

cve-icon NVD

Status : Received

Published: 2026-08-05T07:16:35.570

Modified: 2026-08-05T16:16:52.180

Link: CVE-2026-16561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T20:00:12Z

Weaknesses