Impact
The Sunshine Photo Cart WordPress plugin versions before 3.7 fails to validate that a client‑supplied price identifier belongs to the item being purchased when it is added to the cart. An unauthenticated user can therefore supply a price identifier that corresponds to a lower price defined elsewhere on the site. This allows the user to buy items at that lower price and complete the order, directly causing financial loss for the site owner.
Affected Systems
WordPress sites running the Sunshine Photo Cart plugin with a version older than 3.7, including all releases 3.6 and earlier, are affected. The vulnerability remains present until the plugin is upgraded to version 3.7 or later.
Risk and Exploitability
The EPSS score is 0.00136 (i.e., less than 1%) and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.3 classifies this flaw as moderate severity. Nevertheless, the exploit path is straightforward: an attacker issues a crafted request to the cart endpoint with a manipulated price identifier without needing authentication. This bypasses the intended price validation and can lead to immediate revenue loss. The lack of authentication coupled with the plugin's permissive handling of price IDs makes the vulnerability likely to be abused if discovered by an attacker.
OpenCVE Enrichment