The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_wp_user without any nonce, capability, credential, or ownership verification, while calling wp_set_current_user() and wp_set_auth_cookie() for any WordPress user resolved by the attacker-supplied email address. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by submitting that user's email address.
Metrics
Affected Vendors & Products
References
History
Sat, 15 Aug 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sixstorage
Sixstorage 6storage Rentals Wordpress Wordpress wordpress |
|
| Vendors & Products |
Sixstorage
Sixstorage 6storage Rentals Wordpress Wordpress wordpress |
Sat, 15 Aug 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_wp_user without any nonce, capability, credential, or ownership verification, while calling wp_set_current_user() and wp_set_auth_cookie() for any WordPress user resolved by the attacker-supplied email address. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by submitting that user's email address. | |
| Title | 6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Parameter | |
| Weaknesses | CWE-287 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-08-15T02:26:17.172Z
Reserved: 2026-07-09T16:10:31.973Z
Link: CVE-2026-15303
No data.
Status : Received
Published: 2026-08-15T03:16:47.670
Modified: 2026-08-15T03:16:47.670
Link: CVE-2026-15303
No data.
OpenCVE Enrichment
Updated: 2026-08-15T03:30:01Z