CVE-2025-31084: WordPress Sunshine Photo Cart plugin <= 3.4.10 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through <= 3.4.10.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31084?
CVE-2025-31084 is a critical vulnerability due to the potential for object injection, allowing an attacker to manipulate application behavior.
How do I fix CVE-2025-31084?
To fix CVE-2025-31084, upgrade Sunshine Photo Cart to version 3.4.11 or later, which addresses the deserialization vulnerability.
What versions are affected by CVE-2025-31084?
CVE-2025-31084 affects all versions of Sunshine Photo Cart from n/a through 3.4.10.
What is the impact of CVE-2025-31084?
The impact of CVE-2025-31084 includes potential remote code execution and unauthorized access due to untrusted data deserialization.
Is CVE-2025-31084 an issue only for Sunshine Photo Cart?
Yes, CVE-2025-31084 specifically affects the Sunshine Photo Cart plugin, particularly in its versions up to 3.4.10.