OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-93617

HIGH · CVSS 7.2 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Sunshine Photo Cart plugin is vulnerable to a deserialization of untrusted data issue, allowing for potential object injection attacks. This vulnerability can lead to unauthorized access or manipulation of the application, posing a significant risk to users running versions up to 3.7.1. Organizations utilizing this plugin should prioritize immediate updates or mitigations to safeguard against potential exploitation.

CVE
CVE-2026-93617
Severity
HIGH
CVSS
7.2
EPSS
0.30%

Original NVD Description

Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1.