WordPress security by component
6storage-rentals
Plugin description
6storage-rentals is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Aug 15, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
6storage-rentalsLatest vulnerability
CVE-2026-15303: 6Storage public user creation action permits arbitrary account login
6Storage Rentals through 2.27.0 registers six_storage_create_wp_user on wp_ajax_nopriv without nonce, credential, capability, or ownership validation. The handler resolves the attacker-supplied email address to a WordPress user, then calls wp_set_current_user() and wp_set_auth_cookie() for that account. An unauthenticated attacker who knows an administrator's email can therefore log in as that administrator. Other request fields are not disclosed.
| Safe version |
|
||
|---|---|---|---|
| Aug 15, 2026 |
CVE-2026-15303
6Storage public user creation action permits arbitrary account login
6Storage Rentals through 2.27.0 registers six_storage_create_wp_user on wp_ajax_nopriv without nonce, credential, capability, or ownership validation. The handler resolves the attacker-supplied email address to a WordPress user, then calls wp_set_current_user() and wp_set_auth_cookie() for that account. An unauthenticated attacker who knows an administrator's email can therefore log in as that administrator. Other request fields are not disclosed.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Jun 09, 2026 |
CVE-2026-9185
6Storage Rentals: A security weakness
6Storage Rentals is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.22.0.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Dec 24, 2025 |
CVE-2025-67623
6Storage Rentals: Server-side request forgery
6Storage Rentals is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jun 06, 2025 |
CVE-2023-26002
6Storage Rentals: A security weakness
6Storage Rentals is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVDPending
|
| May 23, 2025 |
CVE-2025-47619
6Storage Rentals: Filesystem traversal
6Storage Rentals is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 04, 2025 |
CVE-2025-32178
6Storage Rentals: A security weakness
6Storage Rentals is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.4
NVDPending
|