CVE-2026-15303 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 10:04am

A security flaw has been identified in the 6Storage Rentals plugin for WordPress, affecting all versions up to and including 2.27.0. The vulnerability allows anyone without a valid login for your website to access a built-in plugin function that has no required verification steps. If an attacker submits the email address of any existing user on your WordPress site (including administrator accounts), they can be automatically logged in as that user, with full access to all permissions that account holds. This means an attacker could take full control of your site’s admin area, make unauthorized changes, access private data, or take other harmful actions if they know the email address of any user with access to your site.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15303

« Back