Sunshine Photo Cart AJAX access exposes restricted-gallery comments
Sunshine Photo Cart before 3.6.12 exposes an AJAX action without an access-control check. An unauthenticated caller can use it to retrieve comments attached to images in private, password-protected or otherwise restricted galleries. This unscored record received deeper review because it provides an unauthenticated protected-content disclosure primitive. The CNA does not disclose the AJAX action, image identifier parameter or response structure.
- Component
- Sunshine Photo Cart
- Plugin slug
sunshine-photo-cart- Affected
- < 3.6.12
- Safe version
3.6.12- Published
- Aug 05, 2026
- Weakness
- CWE-862 — Missing Authorization
This CVE was published Aug 05, 2026 and is one of 24 known issues for this plugin.
Update, patch or deactivate.
Update Sunshine Photo Cart to 3.6.12 or later. Review comments in restricted galleries for sensitive information and inspect historical AJAX traffic if a vulnerable release was publicly accessible.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N