Executive brief
Sunshine Photo Cart is a WordPress plugin used by photographers to create galleries and sell photos online. A security flaw in the plugin's access control settings allows logged-in users with low-level permissions, such as subscribers, to perform actions they should not be authorized to do. This could lead to unauthorized changes to the store configuration or access to restricted photo gallery data.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Sunshine Photo Cart plugin for WordPress in versions up to and including 3.6.7. The flaw stems from insufficient permission checks on certain functions, allowing an authenticated attacker with Subscriber-level privileges to bypass intended access restrictions. By sending crafted network requests, an attacker can execute actions or access data typically reserved for higher-privileged roles. The issue is resolved in version 3.6.8.
Affected products
- WP Sunshine Sunshine Photo Cart up to 3.6.7
Timeline
- 2026-05-25: disclosed: Vulnerability reported by Patchstack researcher
- 2026-05-25: advisory: CVE-2026-42776 published
- 2026-06-02: patched: Version 3.6.8 released to address the issue