This issue affects Sunshine Photo Cart: from n/a through 3.6.7.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the WordPress Sunshine Photo Cart Plugin to the latest available version (at least 3.6.8).
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 27 May 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sunshinephotocart
Sunshinephotocart sunshine Photo Cart Wordpress Wordpress wordpress |
|
| Vendors & Products |
Sunshinephotocart
Sunshinephotocart sunshine Photo Cart Wordpress Wordpress wordpress |
Tue, 26 May 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sunshine Photo Cart: from n/a through 3.6.7. | |
| Title | WordPress Sunshine Photo Cart plugin <= 3.6.7 - Broken Access Control vulnerability | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-05-26T10:50:00.472Z
Reserved: 2026-04-29T11:42:26.336Z
Link: CVE-2026-42776
Updated: 2026-05-26T10:49:55.840Z
Status : Deferred
Published: 2026-05-25T23:16:33.200
Modified: 2026-06-17T10:48:23.397
Link: CVE-2026-42776
No data.
OpenCVE Enrichment
Updated: 2026-05-27T09:45:30Z