CVE-2026-15303 (matched: wordpress)

  • Saturday, 15th August, 2026
  • 16:05pm

A security vulnerability has been found in the 6Storage Rentals plugin for WordPress, affecting all versions up to and including 2.27.0. This is an authentication bypass flaw, which allows unauthorized people to access your site without needing valid login credentials.

If you use the 6Storage Rentals plugin on your WordPress site, you may be impacted by this issue. Attackers do not need any prior access to your site to exploit this flaw: they can log in as any existing user on your site, including administrators, simply by submitting that user's email address.

If an attacker gains administrative control of your site, they can take full control of your website. This could allow them to alter or delete your content, access private data belonging to you or your visitors, or use your site to distribute harmful content to people who visit it.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15303

« Back