PT-2026-72144 · WordPress · 6Storage Rentals
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
6Storage Rentals versions prior to 2.27.1
Description
An authentication bypass exists that allows unauthenticated attackers to log in as any existing WordPress user, including administrators. The issue occurs because the
six storage create wp user() function is registered on the wp ajax nopriv six storage create wp user AJAX endpoint without requiring a nonce, capability, credential, or ownership verification. By providing a target user's email address via the email parameter, an attacker can trigger wp set current user() and wp set auth cookie() to gain unauthorized access.Recommendations
Update to a version newer than 2.27.0.
As a temporary workaround, restrict access to the
wp ajax nopriv six storage create wp user endpoint to minimize the risk of exploitation.Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
6Storage Rentals