Impact
The vulnerability is a missing authorization flaw that allows attackers to bypass correctly configured access control mechanisms within the Sunshine Photo Cart plugin. It permits unauthorized users to access or modify protected resources that should be restricted. This flaw can lead to data exposure or tampering, impacting confidentiality, integrity, and potentially availability of the photo cart data. The weakness is identified as CWE‑862 Authentication Failures.
Affected Systems
Sunshine Photo Cart plugin for WordPress, versions up through 3.5.7.2. The issue affects any site running this plugin that has not been updated beyond that version.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests the likelihood of exploitation remains low under current threat intelligence. The vulnerability is not listed in CISA's KEV catalog, implying no publicly known exploit yet. Attackers would typically need to interact with the plugin's web interface, exploit the misconfigured access control to gain elevated permissions. No specific exploit code is known, so the risk is largely dependent on the plugin's deployment context and user permissions.
OpenCVE Enrichment