Impact
The vulnerability is a broken access control flaw that allows a subscriber user to perform actions or view data that should be restricted, effectively elevating privileges within the Sunshine Photo Cart plugin. This flaw is classified under CWE-862, which denotes improper authorization checks, and compromises the confidentiality and integrity of photo cart data. Based on the description, it is inferred that an attacker must be authenticated as a subscriber to exploit the vulnerability.
Affected Systems
WordPress sites running the Sunshine Photo Cart plugin version 3.6.10.1 or earlier are affected. The issue exists only in the specified versions and is present in all installs of that plugin for WordPress.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The flaw is not included in the CISA KEV catalog. Exploitation requires an authenticated subscriber session, and the attacker would need to access the plugin’s internal functionality to bypass restriction checks. Based on the description, it is inferred that the attacker must navigate the plugin’s internal interface to bypass the authorization checks. The limited exploitation probability and lack of public exploit evidence further reduce the overall threat, but the potential for unauthorized data exposure warrants prompt remediation.
OpenCVE Enrichment