CVE-2026-85037
Deferred Deferred - Pending Action

Unauthenticated Price Manipulation in Sunshine Photo Cart WordPress Plugin

Vulnerability report for CVE-2026-85037, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: WPScan

Description

The Sunshine Photo Cart WordPress plugin before 3.7 does not validate that a client-supplied price identifier belongs to the item being purchased when it is added to the cart, allowing unauthenticated users to buy items at a lower price defined elsewhere on the site and complete an order at that price, resulting in financial loss for the site owner.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sunshine_photo_cart 3.7 to 3.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Sunshine Photo Cart WordPress plugin before version 3.7 has an Insecure Direct Object Reference (IDOR) vulnerability. It fails to validate if a price identifier provided by a user matches the item being purchased. This allows unauthenticated users to add items to the cart at lower prices defined elsewhere on the site, enabling them to complete purchases at those reduced prices and causing financial loss for the site owner.

Detection Guidance

Check if the Sunshine Photo Cart plugin version is below 3.7 using WordPress admin panel or run: wp plugin list | grep sunshine_photo_cart in WP-CLI. Inspect network requests during checkout for price manipulation attempts.

Impact Analysis

If you are a site owner using the Sunshine Photo Cart plugin before version 3.7, attackers could exploit this to purchase items at lower prices, resulting in financial losses. If you are a user, your transactions might be affected if the site owner increases prices to compensate for losses.

Compliance Impact

This vulnerability primarily impacts financial integrity and access control, which may indirectly affect compliance with standards like GDPR or HIPAA if financial data is involved. However, the CVE description does not explicitly link this issue to these regulations. Financial loss from unauthorized price manipulation could raise concerns under data protection laws if customer payment data is compromised, but no direct evidence is provided.

Mitigation Strategies

Update the Sunshine Photo Cart plugin to version 3.7 or later immediately. Disable the plugin temporarily if an update is not immediately available. Review recent orders for suspicious low-price transactions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85037. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart