๐Ÿ” CVE Alert

CVE-2026-85037

MEDIUM 5.3

Sunshine Photo Cart < 3.7 - Unauthenticated Price Manipulation via IDOR

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Sunshine Photo Cart WordPress plugin before 3.7 does not validate that a client-supplied price identifier belongs to the item being purchased when it is added to the cart, allowing unauthenticated users to buy items at a lower price defined elsewhere on the site and complete an order at that price, resulting in financial loss for the site owner.

Vendor unknown
Product sunshine photo cart
Published Sep 9, 2026
Last Updated Sep 9, 2026
Stay Ahead of the Next One

Get instant alerts for unknown sunshine photo cart

Be the first to know when new medium vulnerabilities affecting unknown sunshine photo cart are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Sunshine Photo Cart
0 < 3.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/81201a99-0fbd-494a-9d65-b285a2172224/

Credits

Farid Narimanov WPScan