CVE-2026-39564
Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers
Minimum safe version
3.6.2
Update to 3.6.2 or later to address 28 fixable vulnerabilities
CVE-2025-67973
CVE-2026-24994
Sunshine Photo Cart <= 3.5.7.1 - Missing Authorization
CVE-2025-62892
Sunshine Photo Cart <= 3.4.11 - Authenticated (Subscriber+) Privilege Escalation
CVE-2025-31084
CVE-2024-50463
CVE-2024-49697
CVE-2024-47314
CVE-2024-44038
CVE-2024-43971
CVE-2024-43136
CVE-2024-30221
CVE-2024-30194
CVE-2024-1294
CVE-2023-41796
CVE-2021-4415
CVE-2021-4342
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
CVE-2022-4301
CVE-2022-45826
CVE-2022-40692
Sunshine Photo Cart <= 2.9.14 - Reflected Cross-Site Scripting
WordPress Sunshine Photo Cart Plugin <= 2.9.13 is vulnerable to Broken Access Control
WordPress Sunshine Photo Cart Plugin <= 2.9.13 is vulnerable to Cross Site Request Forgery (CSRF)
CSRF Bypass in Multiple Plugins
WordPress Sunshine Photo Cart plugin <= 2.8.28 - Cross-Site Request Forgery (CSRF) vulnerability