First published: Tue Feb 20 2024(Updated: )
The Sunshine Photo Cart: Free Client Galleries for Photographers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.24 via the 'invoice'. This makes it possible for unauthenticated attackers to extract sensitive data including customer email and physical addresses.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sunshine Photo Cart Free Client Galleries for Photographers | <=3.0.24 | |
WP Sunshine Sunshine Photo Cart | <3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1294 is rated as a critical vulnerability due to its potential for sensitive data exposure.
To fix CVE-2024-1294, update the Sunshine Photo Cart plugin to the latest version beyond 3.0.24.
Any WordPress site using the Sunshine Photo Cart plugin version 3.0.24 or earlier is affected by CVE-2024-1294.
CVE-2024-1294 allows unauthenticated attackers to access sensitive information, including customer email addresses.
The best workaround for CVE-2024-1294 is to disable the Sunshine Photo Cart plugin until it is updated.