CVE-2026-85037

The Sunshine Photo Cart WordPress plugin before 3.7 does not validate that a client-supplied price identifier belongs to the item being purchased when it is added to the cart, allowing unauthenticated users to buy items at a lower price defined elsewhere on the site and complete an order at that price, resulting in financial loss for the site owner.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 06:17

Updated : 2026-09-09 16:17


NVD link : CVE-2026-85037

Mitre link : CVE-2026-85037

CVE.ORG link : CVE-2026-85037


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key