Broken Access Control in Sunshine Photo Cart by Sunshine Apps
CVE-2026-57703

6.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 July 2026

What is CVE-2026-57703?

A vulnerability exists in Sunshine Photo Cart versions up to 3.6.10.1, where improper access controls allow unauthorized users to access restricted functionalities. This flaw can lead to exposure of sensitive data and manipulation of user permissions, highlighting the importance of implementing robust access controls to protect user data and application integrity.

Affected Version(s)

Sunshine Photo Cart <= 3.6.10.1

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dutafi | Patchstack Bug Bounty Program
.