VendorsSunshine Photo Cartsunshine_photo_cartany version
Vulnerabilities

Sunshine Photo Cart Sunshine Photo Cart any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2025-31084
WordPress Sunshine Photo Cart plugin <= 3.4.10 - PHP Object Injection Vulnerability
Published 2025-04-01 · Modified
9.8EPSS 0.007
CVE-2024-30221
WordPress Sunshine Photo Cart plugin <= 3.1.1 - PHP Object Injection vulnerability
Published 2024-03-28 · Modified
9.8EPSS 0.005
CVE-2024-44038
WordPress Sunshine Photo Cart plugin <= 3.2.9 - Broken Access Control vulnerability
Published 2024-11-01 · Modified
9.8EPSS 0.004
CVE-2025-5482
Sunshine Photo Cart <= 3.4.11 - Authenticated (Subscriber+) Privilege Escalation
Published 2025-06-04 · Analyzed
8.8EPSS 0.006
CVE-2024-43136
WordPress Sunshine Photo Cart plugin <= 3.2.1 - Broken Access Control vulnerability
Published 2024-11-01 · Modified
8.8EPSS 0.004
CVE-2024-47314
WordPress Sunshine Photo Cart plugin <= 3.2.8 - Broken Access Control vulnerability
Published 2024-11-01 · Modified
8.8EPSS 0.004
CVE-2022-40692
WordPress Sunshine Photo Cart Plugin <= 2.9.13 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-02-02 · Modified
8.8EPSS 0.003
CVE-2024-30194
WordPress Sunshine Photo Cart plugin <= 3.1.1 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-03-27 · Modified
7.1EPSS 0.007
CVE-2024-43971
WordPress Sunshine Photo Cart plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerability
Published 2024-09-17 · Modified
7.1EPSS 0.006
CVE-2023-41796
WordPress Sunshine Photo Cart Plugin < 3.0.0 is vulnerable to Insecure Direct Object References (IDOR)
Published 2023-12-20 · Modified
6.5EPSS 0.004
CVE-2022-4301
Sunshine Photo Cart < 2.9.15 - Reflected XSS
Published 2023-01-09 · Modified
6.1EPSS 0.009
CVE-2024-50463
WordPress Sunshine Photo Cart plugin <= 3.2.9 - Open Redirection vulnerability
Published 2024-10-28 · Modified
6.1EPSS 0.003
CVE-2022-45826
WordPress Sunshine Photo Cart plugin <= 2.9.13 - Auth. Broken Access Control vulnerability
Published 2024-12-13 · Analyzed
5.4EPSS 0.004
CVE-2024-1294
Sunshine Photo Cart: Free Client Galleries for Photographers <= 3.0.24 - Unauthenticated Sensitive Information Exposure via Invoice
Published 2024-02-20 · Modified
5.3EPSS 0.007
CVE-2024-49697
WordPress Sunshine Photo Cart plugin <= 3.2.9 - Broken Access Control vulnerability
Published 2024-11-19 · Modified
4.3EPSS 0.004
CVE-2021-4415
Sunshine Photo Cart <= 2.8.28 - Cross-Site Request Forgery Bypass
Published 2023-07-12 · Modified
4.3EPSS 0.004