- Lana Codes
- Common Vulnerabilities
Sunshine Photo Cart by WP Sunshine <= 2.9.13 - Broken Access Control
LANACOMMONVDB ID: 2481a5b2-bf35-4232-8597-6166b9ee5a92
The plugin does not have authorisation and Cross-Site Request Forgery (CSRF) check in an AJAX action, which could allow any authenticated users, such as subscriber to copy the gallery files to another folder.
You must be log in to view vulnerability details.
Or register a new account.