A security vulnerability has been found in the 6Storage Rentals plugin for WordPress, affecting all versions up to and including 2.27.0. This flaw allows people who do not have authorized access to your website to log in to any existing user account on your WordPress site, including full administrator accounts. To carry out this unauthorized access, an attacker only needs the email address linked to the target account, with no password or additional identity verification required.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15303