WordPress security by component
Sunshine Photo Cart
Plugin description
Sunshine Photo Cart is a WordPress component with 23 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
sunshine-photo-cartLatest vulnerability
CVE-2026-57703: Sunshine Photo Cart: A security weakness
Sunshine Photo Cart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.6.10.1.
| Safe version |
|
||
|---|---|---|---|
| Jul 23, 2026 |
CVE-2026-57703
Sunshine Photo Cart: A security weakness
Sunshine Photo Cart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.6.10.1.
|
3.6.11 |
CVE6.3
NVDPending
|
| May 25, 2026 |
CVE-2026-42776
Sunshine Photo Cart: A security weakness
Sunshine Photo Cart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.6.7.
|
3.6.8 |
CVE6.3
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39564
Sunshine Photo Cart: A security weakness
Sunshine Photo Cart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.6.2.
|
3.6.2 |
CVE5.3
NVDPending
|
| Feb 20, 2026 |
CVE-2025-67973
Sunshine Photo Cart: A security weakness
Sunshine Photo Cart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Feb 03, 2026 |
CVE-2026-24994
Sunshine Photo Cart: A security weakness
Sunshine Photo Cart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 24, 2025 |
CVE-2025-68535
Sunshine Photo Cart: A security weakness
Sunshine Photo Cart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 27, 2025 |
CVE-2025-62892
Sunshine Photo Cart: A security weakness
Sunshine Photo Cart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jun 04, 2025 |
CVE-2025-5482
Sunshine Photo Cart: Free Client Photo Galleries for Photographers: Privilege escalation or authentication bypass
Sunshine Photo Cart: Free Client Photo Galleries for Photographers is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Apr 01, 2025 |
CVE-2025-31084
Sunshine Photo Cart: Code execution
Sunshine Photo Cart is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Dec 13, 2024 |
CVE-2022-45826
Sunshine Photo Cart: A security weakness
Sunshine Photo Cart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Nov 19, 2024 |
CVE-2024-49697
Sunshine Photo Cart: A security weakness
Sunshine Photo Cart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Nov 01, 2024 |
CVE-2024-47314
Sunshine Photo Cart: A security weakness
Sunshine Photo Cart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.1
NVD8.8
|
| Nov 01, 2024 |
CVE-2024-44038
Sunshine Photo Cart: A security weakness
Sunshine Photo Cart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD9.8
|
| Nov 01, 2024 |
CVE-2024-43136
Sunshine Photo Cart: A security weakness
Sunshine Photo Cart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Oct 28, 2024 |
CVE-2024-50463
Sunshine Photo Cart: An open redirect
Sunshine Photo Cart is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVE4.7
NVD6.1
|
| Sep 18, 2024 |
CVE-2024-43971
Sunshine Photo Cart: Cross-site scripting
Sunshine Photo Cart is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Mar 28, 2024 |
CVE-2024-30221
Sunshine Photo Cart: Code execution
Sunshine Photo Cart is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE5.4
NVD9.8
|
| Mar 27, 2024 |
CVE-2024-30194
Sunshine Photo Cart: Cross-site scripting
Sunshine Photo Cart is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Feb 29, 2024 |
CVE-2024-1294
Sunshine Photo Cart: Free Client Galleries for Photographers: Sensitive information exposure
Sunshine Photo Cart: Free Client Galleries for Photographers is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 20, 2023 |
CVE-2023-41796
Sunshine Photo Cart: Free Client Galleries for Photographers: A security weakness
Sunshine Photo Cart: Free Client Galleries for Photographers is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD6.5
|
| Jul 12, 2023 |
CVE-2021-4415
Sunshine Photo Cart: Cross-site request forgery
Sunshine Photo Cart is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Feb 02, 2023 |
CVE-2022-40692
Sunshine Photo Cart: Cross-site request forgery
Sunshine Photo Cart is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Jan 09, 2023 |
CVE-2022-4301
Sunshine Photo Cart: Cross-site scripting
Sunshine Photo Cart is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|