A security vulnerability has been found in the 6Storage Rentals plugin for WordPress, affecting all versions up to and including 2.27.0. This flaw allows anyone without an existing account on your WordPress site to log in as any registered user, including site administrators, by only submitting that user's email address. No valid login credentials, verification steps, or proof of identity are required to exploit this weakness. If an attacker gains administrator access through this method, they could modify your site’s content, access private information stored on your WordPress installation, or take full control of your website.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15303