Sunshine Photo Cart Plugin Sensitive Data Exposure Vulnerability

Vulnerability

A vulnerability allowing the retrieval of embedded sensitive data has been identified in the Sunshine Photo Cart WordPress plugin, affecting versions prior to 3.6.2. This issue allows unauthorized users to access sensitive information that is typically restricted.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, which could be used to exploit other weaknesses in the system.

Remediation

Users of the Sunshine Photo Cart WordPress plugin should update to version 3.6.2 or later. Patchstack users can enable auto-update for vulnerable plugins.

Added: Apr 8, 2026, 11:19 AM
Updated: Apr 8, 2026, 11:19 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
7.6
remediation
7.7
relevance
5.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.