← WordPress Vulnerabilities
WordPress security by component

6storage-rentals

6storage-rentals is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Aug 15, 2026; the highest published CVSS base score is 9.8.

Plugin slug: 6storage-rentals

CVE-2026-15303: 6Storage public user creation action permits arbitrary account login

6Storage Rentals through 2.27.0 registers six_storage_create_wp_user on wp_ajax_nopriv without nonce, credential, capability, or ownership validation. The handler resolves the attacker-supplied email address to a WordPress user, then calls wp_set_current_user() and wp_set_auth_cookie() for that account. An unauthenticated attacker who knows an administrator's email can therefore log in as that administrator. Other request fields are not disclosed.

PublishedAug 15, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for 6storage-rentals
Safe version
Aug 15, 2026 CVE-2026-15303
6Storage public user creation action permits arbitrary account login
6Storage Rentals through 2.27.0 registers six_storage_create_wp_user on wp_ajax_nopriv without nonce, credential, capability, or ownership validation. The handler resolves the attacker-supplied email address to a WordPress user, then calls wp_set_current_user() and wp_set_auth_cookie() for that account. An unauthenticated attacker who knows an administrator's email can therefore log in as that administrator. Other request fields are not disclosed.
See mitigation notes
CVE9.8
NVDPending
Jun 09, 2026 CVE-2026-9185
6Storage Rentals: A security weakness
6Storage Rentals is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.22.0.
See mitigation notes
CVE7.5
NVDPending
Dec 24, 2025 CVE-2025-67623
6Storage Rentals: Server-side request forgery
6Storage Rentals is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.4
NVDPending
Jun 06, 2025 CVE-2023-26002
6Storage Rentals: A security weakness
6Storage Rentals is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVDPending
May 23, 2025 CVE-2025-47619
6Storage Rentals: Filesystem traversal
6Storage Rentals is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending
Apr 04, 2025 CVE-2025-32178
6Storage Rentals: A security weakness
6Storage Rentals is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.4
NVDPending