CyberRota Analysis
AI-GeneratedThe Sunshine Photo Cart plugin for WordPress prior to version 3.6.12 lacks proper access control in its AJAX actions, enabling unauthenticated users to access comments from images in private or password-protected galleries. This vulnerability can lead to unauthorized exposure of sensitive information, making it critical for website administrators using this plugin to prioritize updates to safeguard user privacy and data integrity.
Original NVD Description
The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.