Junglewise Threat Intelligence

CVE-2026-57703: WP Sunshine Sunshine Photo Cart broken access control

CVE-2026-57703 · Severity: medium · CVSS 6.3 · Published 2026-07-23

Technologies: WP Sunshine Sunshine Photo Cart. Vendors: WP Sunshine.

Executive brief

Sunshine Photo Cart is a WordPress plugin used by photographers to create galleries and sell photos online. A security flaw in versions up to 3.6.10.1 allows users with basic 'Subscriber' accounts to perform actions they should not be authorized to do. This could lead to unauthorized changes to the store settings or access to restricted data, potentially impacting the integrity of the photography business operations.

Technical details

A broken access control vulnerability (CWE-862: Missing Authorization) exists in the Sunshine Photo Cart plugin for WordPress. The flaw is present in versions up to and including 3.6.10.1. It allows a remote attacker with 'Subscriber' level privileges to bypass intended access restrictions due to insufficient authorization checks within the plugin's functions. An attacker can exploit this to execute actions that should be reserved for higher-privileged users, potentially leading to unauthorized data modification or disclosure. The issue is resolved in version 3.6.11.

Affected products

  • WP Sunshine Sunshine Photo Cart <= 3.6.10.1

Timeline

  • 2026-06-16: disclosed: Reported by researcher dutafi
  • 2026-07-20: advisory: Patchstack published advisory
  • 2026-07-23: advisory: NVD published CVE record
  • 2026-07-23: patched: Patch confirmed available in version 3.6.11

References

Related threats