What is CVE-2026-16561?
CVE-2026-16561 is a vulnerability in the Sunshine Photo Cart WordPress plugin before version 3.6.12, caused by missing access control checks in an AJAX action. It allows unauthenticated users to retrieve image comments from private, password-protected, or otherwise access-restricted galleries. Users should update the plugin to version 3.6.12 or later.
Azərbaycanca: CVE-2026-16561 WordPress üçün Sunshine Photo Cart plaginində (3.6.12-dən əvvəlki versiyalar) müəyyən edilmiş zəiflikdir. Bu zəiflik AJAX action-da access control yoxlanışının olmaması səbəbindən autentifikasiya olunmamış istifadəçilərə qapalı, parolla qorunan və ya girişi məhdudlaşdırılmış qalereyalardakı şəkil şərhlərini oxumağa imkan verir. Plagini ən azı 3.6.12 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin is affected by CVE-2026-16561?
This vulnerability affects the Sunshine Photo Cart plugin for WordPress.
What can an unauthenticated user achieve by successfully exploiting CVE-2026-16561?
An unauthenticated user can retrieve image comments from private, password-protected, or otherwise access-restricted galleries.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.