A security flaw has been identified in the 6Storage Rentals plugin for WordPress, impacting all versions up to and including 2.27.0. This vulnerability allows anyone without a valid account for your WordPress site to log in as any existing user, including site administrators, by only providing that user’s email address. The issue stems from a public, no-login-required feature of the plugin that does not perform any identity verification, permission checks, or credential validation. When an email address is submitted to this feature, it automatically logs in the user associated with that email, with no password or other proof of identity needed from the person making the request.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15303