What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in WP Sunshine Sunshine Photo Cart: Free Client Galleries for Photographers.This issue affects Sunshine Photo Cart: Free Client Galleries for Photographers: from n/a before 3.0.0.
Explanation of Vulnerability in Simple Terms
02Summary
Sunshine Photo Cart versions before 3.0.0 contain an authorization bypass that allows unauthenticated attackers to modify gallery data over the network. The vulnerability requires no user interaction and can be exploited remotely. Site owners should update to version 3.0.0 or later immediately.
What an attacker can do
03Attacker Capabilities
Modify gallery content and settings without authentication.
Potential impact on your site
04Site Impact
Attackers can alter or deface client galleries without logging in, damaging photographer portfolios and client trust.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
December 20, 2023
CVE published
April 28, 2026
Record updated