Missing Authorization Vulnerability Affects Sunshine Photo Cart
CVE-2024-47314

8.8HIGH

Key Information:

Vendor
WP Sunshine
Status
Sunshine Photo Cart
Vendor
CVE Published:
1 November 2024

Summary

A missing authorization vulnerability has been identified in the Sunshine Photo Cart plugin developed by WP Sunshine, which enables attackers to exploit incorrectly configured access control security levels. This flaw allows unauthorized access to sensitive features and functionality within the Sunshine Photo Cart. The affected versions range from n/a up to 3.2.8. Implementing proper access control mechanisms is crucial to mitigate the risk posed by this vulnerability, ensuring that users have appropriate permissions based on their roles.

Affected Version(s)

Sunshine Photo Cart <= 3.2.8

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)
.