CVE-2024-1294: Sunshine Photo Cart: Free Client Galleries for Photographers <= 3.0.24 - Unauthenticated Sensitive Information Exposure via Invoice
The Sunshine Photo Cart: Free Client Galleries for Photographers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.24 via the 'invoice'. This makes it possible for unauthenticated attackers to extract sensitive data including customer email and physical addresses.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1294?
CVE-2024-1294 is rated as a critical vulnerability due to its potential for sensitive data exposure.
How do I fix CVE-2024-1294?
To fix CVE-2024-1294, update the Sunshine Photo Cart plugin to the latest version beyond 3.0.24.
Who is affected by CVE-2024-1294?
Any WordPress site using the Sunshine Photo Cart plugin version 3.0.24 or earlier is affected by CVE-2024-1294.
What data is vulnerable in CVE-2024-1294?
CVE-2024-1294 allows unauthenticated attackers to access sensitive information, including customer email addresses.
Is there a workaround for CVE-2024-1294?
The best workaround for CVE-2024-1294 is to disable the Sunshine Photo Cart plugin until it is updated.