CVE-2026-24994: WordPress Sunshine Photo Cart plugin <= 3.5.7.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24994?
The CVE-2026-24994 vulnerability has a high severity rating due to its broken access control issue that could lead to unauthorized access.
How do I fix CVE-2026-24994?
To fix CVE-2026-24994, upgrade the Sunshine Photo Cart plugin to version 3.5.7.3 or later, which addresses the access control flaws.
Who is affected by CVE-2026-24994?
All users of the Sunshine Photo Cart plugin version 3.5.7.2 and earlier are affected by CVE-2026-24994.
What type of vulnerability is CVE-2026-24994?
CVE-2026-24994 is classified as a Broken Access Control vulnerability, which involves inadequate restriction of resource access.
What impact can CVE-2026-24994 have on my website?
If exploited, CVE-2026-24994 can allow attackers to bypass authorization and access sensitive data or functionalities on your website.