CVE-2026-93617: WordPress Sunshine Photo Cart plugin <= 3.7.1 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
sunshine-photo-cartto a version that resolves this vulnerability.Fixed in 3.7.2
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability requires high privileges (PR:H). It is remotely reachable and does not require user interaction, but an unauthenticated attacker is not indicated as able to exploit it.
Which plugin versions are affected?
Sunshine Photo Cart versions through 3.7.1 are affected. The available data does not identify a fixed version.
What is the potential impact if exploitation succeeds?
Successful exploitation can affect confidentiality, integrity, and availability at a high level. The issue is classified as PHP object injection caused by deserialization of untrusted data.