Missing Authorization Vulnerability Affects Sunshine Photo Cart
CVE-2024-47314
8.8HIGH
Key Information:
- Vendor
- WP Sunshine
- Status
- Sunshine Photo Cart
- Vendor
- CVE Published:
- 1 November 2024
Summary
A missing authorization vulnerability has been identified in the Sunshine Photo Cart plugin developed by WP Sunshine, which enables attackers to exploit incorrectly configured access control security levels. This flaw allows unauthorized access to sensitive features and functionality within the Sunshine Photo Cart. The affected versions range from n/a up to 3.2.8. Implementing proper access control mechanisms is crucial to mitigate the risk posed by this vulnerability, ensuring that users have appropriate permissions based on their roles.
Affected Version(s)
Sunshine Photo Cart <= 3.2.8
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)