Insufficient Price Validation in Sunshine Photo Cart Plugin for WordPress
CVE-2026-85037

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-85037?

The Sunshine Photo Cart plugin for WordPress prior to version 3.7 is susceptible to a vulnerability that arises due to insufficient validation of client-supplied price identifiers. This flaw allows unauthenticated users to manipulate price information during the cart process, enabling them to purchase items at artificially lowered prices. As a consequence, website owners face potential financial losses, as unauthorized transactions can undermine pricing integrity. It is critical for users of the Sunshine Photo Cart to update to the latest version to mitigate this risk.

Affected Version(s)

Sunshine Photo Cart 0 < 3.7

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Farid Narimanov
WPScan
.