Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Sunshine Photo Cart — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in Sunshine Photo Cart, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the Sunshine Photo Cart product, specifically categorizing security weaknesses associated with this vendor's hardware and software components under defined weakness types and tags. The collection includes both historical and recent advisories, spanning from the initial release through the latest updates, covering issues such as buffer overflows, authentication flaws, and configuration errors. Readers can use this resource to track the vendor’s published security advisories, understand the characteristics of a specific weakness class, and review the complete vulnerability history for the Sunshine Photo Cart. The data is structured to support rapid assessment of exposure and remediation needs, providing a centralized view of all known defects without requiring a search across multiple sources.

Vendor: WP Sunshine

CVE ID Title CVSS Severity Published
CVE-2026-85037 Sunshine Photo Cart < 3.7 - Unauthenticated Price Manipulation via IDOR - - 2026-09-09
CVE-2026-16561 Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure - - 2026-08-05
CVE-2026-57703 WordPress Sunshine Photo Cart plugin <= 3.6.10.1 - Broken Access Control vulnerability CWE-862 6.3 Medium 2026-07-23
CVE-2026-42776 WordPress Sunshine Photo Cart plugin <= 3.6.7 - Broken Access Control vulnerability CWE-862 6.3 Medium 2026-05-25
CVE-2026-39564 WordPress Sunshine Photo Cart plugin < 3.6.2 - Sensitive Data Exposure vulnerability CWE-201 5.3 Medium 2026-04-08
CVE-2025-67973 WordPress Sunshine Photo Cart plugin <= 3.5.6.2 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-02-20
CVE-2026-24994 WordPress Sunshine Photo Cart plugin <= 3.5.7.2 - Broken Access Control vulnerability CWE-862 5.3 Medium 2026-02-03
CVE-2025-68535 WordPress Sunshine Photo Cart plugin <= 3.5.7.1 - Broken Access Control vulnerability CWE-862 4.3 Medium 2025-12-24
CVE-2025-62892 WordPress Sunshine Photo Cart plugin <= 3.5.3 - Broken Access Control vulnerability CWE-862 5.3 Medium 2025-10-27
CVE-2025-31084 WordPress Sunshine Photo Cart plugin <= 3.4.10 - PHP Object Injection Vulnerability CWE-502 9.8 Critical 2025-04-01
CVE-2022-45826 WordPress Sunshine Photo Cart plugin <= 2.9.13 - Auth. Broken Access Control vulnerability CWE-862 5.4 Medium 2024-12-13
CVE-2024-49697 WordPress Sunshine Photo Cart plugin <= 3.2.9 - Broken Access Control vulnerability CWE-862 4.3 Medium 2024-11-19
CVE-2024-47314 WordPress Sunshine Photo Cart plugin <= 3.2.8 - Broken Access Control vulnerability CWE-862 7.1 High 2024-11-01
CVE-2024-44038 WordPress Sunshine Photo Cart plugin <= 3.2.9 - Broken Access Control vulnerability CWE-862 5.3 Medium 2024-11-01
CVE-2024-43136 WordPress Sunshine Photo Cart plugin <= 3.2.1 - Broken Access Control vulnerability CWE-862 4.3 Medium 2024-11-01
CVE-2024-50463 WordPress Sunshine Photo Cart plugin <= 3.2.9 - Open Redirection vulnerability CWE-601 4.7 Medium 2024-10-28
CVE-2024-43971 WordPress Sunshine Photo Cart plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-09-17
CVE-2024-30221 WordPress Sunshine Photo Cart plugin <= 3.1.1 - PHP Object Injection vulnerability CWE-502 5.4 Medium 2024-03-28
CVE-2024-30194 WordPress Sunshine Photo Cart plugin <= 3.1.1 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-03-27
CVE-2022-40692 WordPress Sunshine Photo Cart Plugin <= 2.9.13 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 5.4 Medium 2023-02-02
CVE-2022-4301 Sunshine Photo Cart < 2.9.15 - Reflected XSS 6.1 - 2023-01-09

All 21 known CVE vulnerabilities affecting Sunshine Photo Cart with full Chinese analysis, references, and POCs where available.