AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16561

HIGH · CVSS 7.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Sunshine Photo Cart plugin for WordPress prior to version 3.6.12 lacks proper access control in its AJAX actions, enabling unauthenticated users to access comments from images in private or password-protected galleries. This vulnerability can lead to unauthorized exposure of sensitive information, making it critical for website administrators using this plugin to prioritize updates to safeguard user privacy and data integrity.

CVE
CVE-2026-16561
Severity
HIGH
CVSS
7.5
EPSS
0.30%
WordPress

Original NVD Description

The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.