A security flaw has been identified in the 6Storage Rentals plugin for WordPress, affecting all versions of the plugin up to and including 2.27.0.
This issue allows anyone without existing access to your website to log in as any registered user on your WordPress site, including administrators, simply by entering that user's registered email address. The flaw exists because a public feature of the plugin does not require standard security checks before granting access to user accounts.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15303