Executive brief
Sunshine Photo Cart is a WordPress plugin used by photographers to create galleries and sell photos online. A security vulnerability in versions prior to 3.6.2 allows unauthorized individuals to access sensitive data that should normally be protected. This could lead to the exposure of private customer or gallery information, potentially impacting user privacy and business reputation.
Technical details
The Sunshine Photo Cart plugin for WordPress suffers from an 'Insertion of Sensitive Information Into Sent Data' (CWE-201) vulnerability. This flaw allows an unauthenticated remote attacker to retrieve sensitive data that is inadvertently embedded or included in the data sent by the application. The issue is present in versions up to, but not including, 3.6.2. Attackers can exploit this over the network without any user interaction or special privileges. The vulnerability was addressed in version 3.6.2.
Affected products
- sunshinephotocart Sunshine Photo Cart < 3.6.2
Timeline
- 2026-02-24: disclosed: Reported by Bao - BlueRock via Patchstack
- 2026-03-26: advisory: Patchstack advisory published
- 2026-04-08: advisory: NVD published CVE-2026-39564
- 2026-03-26: patched: Version 3.6.2 released to address the issue