CVE-2026-15303 (matched: wordpress)

  • Saturday, 15th August, 2026
  • 22:04pm

A security flaw has been discovered in the 6Storage Rentals plugin for WordPress, which affects all versions of the plugin up to and including 2.27.0. This vulnerability allows anyone who does not have an account on your website to log in as any existing WordPress user on your site, including administrator accounts, simply by entering that user’s registered email address. No password, verification code, or other proof of identity is needed for this unauthorized access.

If an attacker is able to log in to an administrator account, they can take full control of your website. This means they could change or delete your site’s content, access private information like customer details or business data stored on your site, or alter your site’s core settings. This type of breach can lead to lost data, harm to your business’s reputation, and potential legal or compliance issues for your organization.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15303

« Back