CVE-2026-16561: Unknown Sunshine Photo Cart

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.

Affected products

  • Unknown Sunshine Photo Cart: before 3.6.12 (fixed in 3.6.12)

Published 2026-08-05. Last modified 2026-08-26.