CVE-2026-15303 (matched: wordpress)

  • Monday, 17th August, 2026
  • 10:05am

A security flaw tracked as CVE-2026-15303 impacts the 6Storage Rentals plugin for WordPress, with all versions up to and including 2.27.0 affected. The issue exists in a plugin feature that handles user account logins, which does not require any verification (such as a security check, proof of account ownership, or permission confirmation) before granting access to a WordPress user account. This allows people who do not already have access to your website to log in as any existing WordPress user on your site, including administrators, by only submitting that user's email address. No existing login credentials or special access are needed for an attacker to exploit this vulnerability.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15303

« Back