Missing Authorization Vulnerability Affects Sunshine Photo Cart
CVE-2024-47314
7.1HIGH
What is CVE-2024-47314?
A missing authorization vulnerability has been identified in the Sunshine Photo Cart plugin developed by WP Sunshine, which enables attackers to exploit incorrectly configured access control security levels. This flaw allows unauthorized access to sensitive features and functionality within the Sunshine Photo Cart. The affected versions range from n/a up to 3.2.8. Implementing proper access control mechanisms is crucial to mitigate the risk posed by this vulnerability, ensuring that users have appropriate permissions based on their roles.
Affected Version(s)
Sunshine Photo Cart 0 <= 3.2.8
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)