Vulnerabilities > Sunshinephotocart

DATE CVE VULNERABILITY TITLE RISK
2024-11-01 CVE-2024-44038 Missing Authorization vulnerability in Sunshinephotocart Sunshine Photo Cart
Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 3.2.9.
network
low complexity
sunshinephotocart CWE-862
critical
9.8
2024-11-01 CVE-2024-47314 Missing Authorization vulnerability in Sunshinephotocart Sunshine Photo Cart
Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 3.2.8.
network
low complexity
sunshinephotocart CWE-862
8.8
2024-10-28 CVE-2024-50463 Open Redirect vulnerability in Sunshinephotocart Sunshine Photo Cart
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP Sunshine Sunshine Photo Cart.This issue affects Sunshine Photo Cart: from n/a through 3.2.9.
network
low complexity
sunshinephotocart CWE-601
6.1
2024-09-18 CVE-2024-43971 Cross-site Scripting vulnerability in Sunshinephotocart Sunshine Photo Cart
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Sunshine Sunshine Photo Cart allows Reflected XSS.This issue affects Sunshine Photo Cart: from n/a through 3.2.5.
network
low complexity
sunshinephotocart CWE-79
6.1
2023-12-20 CVE-2023-41796 Authorization Bypass Through User-Controlled Key vulnerability in Sunshinephotocart Sunshine Photo Cart
Authorization Bypass Through User-Controlled Key vulnerability in WP Sunshine Sunshine Photo Cart: Free Client Galleries for Photographers.This issue affects Sunshine Photo Cart: Free Client Galleries for Photographers: from n/a before 3.0.0.
network
low complexity
sunshinephotocart CWE-639
6.5
2023-07-12 CVE-2021-4415 Unspecified vulnerability in Sunshinephotocart Sunshine Photo Cart
The Sunshine Photo Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.28 This is due to missing or incorrect nonce validation on the sunshine_products_quicksave_post() function.
network
low complexity
sunshinephotocart
4.3
2023-02-02 CVE-2022-40692 Cross-Site Request Forgery (CSRF) vulnerability in Sunshinephotocart Sunshine Photo Cart
Cross-Site Request Forgery (CSRF) vulnerability in WP Sunshine Sunshine Photo Cart plugin <= 2.9.13 versions.
network
low complexity
sunshinephotocart CWE-352
8.8
2023-01-09 CVE-2022-4301 Unspecified vulnerability in Sunshinephotocart Sunshine Photo Cart
The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
network
low complexity
sunshinephotocart
6.1