6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Parameter
critical
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_wp_user without any nonce, capability, credential, or ownership verification, whil...
- CVSS:
- 9.8
- Affected:
- up to 2.27.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 14, 2026
CVE-2026-15303 on NVD →
6Storage Rentals <= 2.22.0 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Disclosure and Modification via 'userId' Parameter
high
The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.22.0 via the `userId` parameter of the `six_storage_get_user_info` and `six_storage_update_profile` AJAX actions. This is due to the `six_storage_getUserInfo()` and `six_stor...
- CVSS:
- 7.5
- Affected:
- up to 2.22.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 8, 2026
CVE-2026-9185 on NVD →
6Storage Rentals <= 2.20.0 - Authenticated (Subscriber+) Server-Side Request Forgery
medium
The 6Storage Rentals plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.20.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application which can be u...
- CVSS:
- 6.4
- Affected:
- up to 2.20.0
- Fix:
- No patched version reported
- Disclosed:
- Dec 20, 2025
CVE-2025-67623 on NVD →
6Storage Rentals <= 2.19.6 - Missing Authorization
medium
The 6Storage Rentals plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.19.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.19.6
- Fix:
- No patched version reported
- Disclosed:
- Jun 5, 2025
CVE-2023-26002 on NVD →
6Storage Rentals <= 2.19.4 - Missing Authorization
medium
The 6Storage Rentals plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.19.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.19.4
- Fix:
- No patched version reported
- Disclosed:
- May 16, 2025
CVE-2025-47619 on NVD →
6Storage Rentals <= 2.19.4 - Missing Authorization
medium
The 6Storage Rentals plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.19.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.19.4
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2025
CVE-2025-32178 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database