CVE-2026-39564 MEDIUM

CVE-2026-39564: WordPress Sunshine Photo Cart plugin < 3.6.2 - Sensitive Data Exposure vulnerability

Vendor Sunshinephotocart
Product Sunshine Photo Cart
Weakness CWE-201
Published April 8, 2026
Last update April 29, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Insertion of Sensitive Information Into Sent Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Retrieve Embedded Sensitive Data.This issue affects Sunshine Photo Cart: from n/a through < 3.6.2.

Explanation of Vulnerability in Simple Terms

02Summary

Sunshine Photo Cart versions 3.6.2 and earlier expose sensitive information to unauthenticated attackers over the network. An attacker can read non-critical data without authentication or user interaction. The vulnerability has a CVSS score of 5.3 (medium severity) and affects all versions up to 3.6.2.

What an attacker can do

03Attacker Capabilities

Read sensitive information without authentication.

Potential impact on your site

04Site Impact

Sensitive data may be exposed to anyone on the internet without requiring login.

Conditions required to exploit

05Prerequisites

Network access to the affected Sunshine Photo Cart installation.

Key dates

06Disclosure timeline

April 8, 2026 CVE published
April 29, 2026 Record updated

Related vulnerabilities

08Related CVE