The Sunshine Photo Cart plugin for WordPress has a security flaw that allows unauthorized changes to be made to data. This is because the sunshine_add_to_favorites() function in versions up to 3.2.1 does not have a necessary check in place. This means that attackers who are logged in with a subscriber-level access or higher can mark images in galleries as favorites, even if they do not have permission to access those galleries.