What the vulnerability does
01Description
Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 2.9.13.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 2.9.13.
Explanation of Vulnerability in Simple Terms
Sunshine Photo Cart versions up to 2.9.13 lack proper authorization checks, allowing an unauthenticated attacker to modify or delete data by tricking a user into visiting a malicious link. The vulnerability requires user interaction but can compromise site integrity without authentication.
What an attacker can do
Modify or delete site data by tricking a user into clicking a malicious link.
Potential impact on your site
Unauthorized changes or deletion of photo cart data if users are socially engineered.
Conditions required to exploit
An unauthenticated attacker needs a site user to click a link they provide.
Key dates
External resources
Related vulnerabilities