PoC Index

CVE-2026-16561

HIGH 7.5EPSS 0.3%

The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.30% chance of exploitation in the next 30 days, 22th percentile
Published
2026-08-05

Proof-of-concept exploits (1)

References

Related