CVE-2026-85037 UNKNOWN

CVE-2026-85037

Published: 2026-09-09

Description

The Sunshine Photo Cart WordPress plugin before 3.7 does not validate that a client-supplied price identifier belongs to the item being purchased when it is added to the cart, allowing unauthenticated users to buy items at a lower price defined elsewhere on the site and complete an order at that price, resulting in financial loss for the site owner.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…