CVE-2026-39564: WordPress Sunshine Photo Cart plugin < 3.6.2 - Sensitive Data Exposure vulnerability
Published Apr 8, 2026
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Retrieve Embedded Sensitive Data.This issue affects Sunshine Photo Cart: from n/a through < 3.6.2.
Affected Software
1 affected component
wordpress/sunshine-photo-cart<3.6.2
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39564?
The severity of CVE-2026-39564 is rated medium with a CVSS score of 5.3.
2
What type of vulnerability is CVE-2026-39564?
CVE-2026-39564 is classified as a Sensitive Data Exposure vulnerability.
3
How do I fix CVE-2026-39564?
To fix CVE-2026-39564, upgrade Sunshine Photo Cart to version 3.6.2 or later.
4
Who is affected by CVE-2026-39564?
CVE-2026-39564 affects users of the Sunshine Photo Cart plugin version less than 3.6.2.
5
When was CVE-2026-39564 published?
CVE-2026-39564 was published on April 8, 2026.