The Sunshine Photo Cart plugin for WordPress has a security issue called Reflected Cross-Site Scripting that affects versions up to and including 3.1.1. This happens because the plugin does not properly clean and protect the input and output. As a result, hackers who are not logged in can insert harmful scripts into pages and trick users into clicking on them.