{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/6storage-rentals--2.27.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-15303"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["6Storage Rentals (\u003c= 2.27.0)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","authentication-bypass","web-application-security"],"_cs_type":"advisory","_cs_vendors":["6Storage"],"content_html":"\u003cp\u003eThe 6Storage Rentals plugin for WordPress, in versions up to and including 2.27.0, contains a critical authentication bypass vulnerability identified as CVE-2026-15303. The vulnerability stems from an insecure implementation of the AJAX handler 'six_storage_create_wp_user'. This handler is registered as 'wp_ajax_nopriv_six_storage_create_wp_user', making it accessible to unauthenticated users. The function lacks essential security controls, including nonce verification, capability checks, and authentication requirements.\u003c/p\u003e\n\u003cp\u003eWhen triggered, the handler takes an attacker-supplied email address and uses it to resolve a corresponding WordPress user account. It then invokes 'wp_set_current_user()' and 'wp_set_auth_cookie()' to authenticate the session as that user. Because these functions are executed without validating the caller, an unauthenticated attacker can supply the email address of an administrator to gain full administrative access to the WordPress instance. This vulnerability poses a severe risk to any organization using the affected plugin version.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in full administrative account takeover of the WordPress instance. An attacker can create new administrative users, install malicious plugins, modify site content, or perform site-wide configuration changes. Given the prevalence of WordPress in enterprise environments, this can lead to large-scale data exfiltration, the deployment of backdoors, or the redirection of web traffic to malicious sites.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the 6Storage Rentals plugin to the latest available version beyond 2.27.0 immediately.\u003c/li\u003e\n\u003cli\u003eIf an update is not immediately available, disable the plugin until a patch is applied.\u003c/li\u003e\n\u003cli\u003eAudit existing user accounts for suspicious additions or modifications occurring around the time of potential exposure.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for repeated requests to the 'admin-ajax.php' endpoint with 'action=six_storage_create_wp_user'.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to block POST requests containing the parameter 'action=six_storage_create_wp_user' unless legitimate business needs require its use in a hardened environment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-15T04:16:14Z","date_published":"2026-08-15T04:16:14Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-15303/","summary":"The 6Storage Rentals WordPress plugin contains a critical authentication bypass vulnerability (CVE-2026-15303) that allows unauthenticated attackers to impersonate any user, including administrators, via the six_storage_create_wp_user AJAX handler.","title":"Authentication Bypass in 6Storage Rentals WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-15303/"}],"language":"en","title":"CraftedSignal Threat Feed - 6Storage Rentals (\u003c= 2.27.0)","version":"https://jsonfeed.org/version/1.1"}