๐Ÿ” CVE Alert

CVE-2025-67623

CRITICAL 9.1

WordPress 6Storage Rentals plugin <= 2.20.2 - Server Side Request Forgery (SSRF) vulnerability

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Request Forgery.This issue affects 6Storage Rentals: from n/a through <= 2.20.2.

CWE CWE-918
Vendor 6storage
Product 6storage rentals
Published Dec 24, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for 6storage 6storage rentals

Be the first to know when new critical vulnerabilities affecting 6storage 6storage rentals are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

6Storage / 6Storage Rentals
0 โ‰ค 2.20.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/6storage-rentals/vulnerability/wordpress-6storage-rentals-plugin-2-19-9-server-side-request-forgery-ssrf-vulnerability?_s_id=cve

Credits

Jarno Vos (jrn5151) | Patchstack Bug Bounty Program