Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.5epss 0.3%
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Unknown · Sunshine Photo Cartpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/25bbf054-3b3f-4d88-899e-03d48055cbcd/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.