๐Ÿ” CVE Alert

CVE-2026-15303

CRITICAL 9.8

6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Parameter

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_wp_user without any nonce, capability, credential, or ownership verification, while calling wp_set_current_user() and wp_set_auth_cookie() for any WordPress user resolved by the attacker-supplied email address. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by submitting that user's email address.

CWE CWE-287
Vendor sixstorage
Product 6storage rentals
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for sixstorage 6storage rentals

Be the first to know when new critical vulnerabilities affecting sixstorage 6storage rentals are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

sixstorage / 6Storage Rentals
0 โ‰ค 2.27.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/94e987be-bdfc-4691-b250-2b7d7249df0a?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/6storage-rentals/tags/2.27.0/inc/Base/Six_Storage_DashboardController.php#L3905 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/6storage-rentals/tags/2.27.0/inc/Base/Six_Storage_DashboardController.php#L3834 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/6storage-rentals/tags/2.27.0/inc/Base/Six_Storage_DashboardController.php#L14

Credits

Afan moonge