CVE-2026-16561: Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure
The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sunshine Photo Cart (WordPress plugin)to a version that resolves this vulnerability.Fixed in 3.6.12
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16561?
CVE-2026-16561 has a risk score of 45, indicating a moderate severity level.
How do I fix CVE-2026-16561?
To fix CVE-2026-16561, update the Sunshine Photo Cart WordPress plugin to version 3.6.12 or later.
What does CVE-2026-16561 affect?
CVE-2026-16561 affects the Sunshine Photo Cart WordPress plugin versions prior to 3.6.12.
What type of vulnerability is CVE-2026-16561?
CVE-2026-16561 is an unauthenticated private gallery comment disclosure vulnerability.
Can unauthenticated users exploit CVE-2026-16561?
Yes, unauthenticated users can exploit CVE-2026-16561 to retrieve comments from private galleries.