What is CVE-2026-15303?
CVE-2026-15303 is an authentication bypass vulnerability in the 6Storage Rentals plugin for WordPress up to version 2.27.0. The issue arises because the six_storage_create_wp_user() AJAX handler is registered via wp_ajax_nopriv without any nonce, capability, or ownership checks. Users should update the plugin immediately.
Azərbaycanca: CVE-2026-15303, 6Storage Rentals WordPress plugin-nin 2.27.0 versiyasına qədər olan versiyalarında autentifikasiyadan yan keçmə zəifliyidir. Bu boşluq six_storage_create_wp_user() AJAX handler-inin heç bir nonce, səlahiyyət yoxlaması olmadan wp_ajax_nopriv kimi qeydiyyatdan keçməsi səbəbindən yaranır. Plugin istifadəçiləri dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which function causes the CVE-2026-15303 vulnerability in the 6Storage Rentals WordPress plugin?
The vulnerability arises because the six_storage_create_wp_user() AJAX handler is registered via wp_ajax_nopriv without any nonce, capability, or ownership checks.
What should users do to protect against CVE-2026-15303?
Users should update the 6Storage Rentals plugin to the latest version immediately, as the vulnerability exists in versions up to 2.27.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.