CVE detail
CVE-2026-9185
The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.22.0 via the `userId` parameter of the `six_storage_get_user_info` and `six_storage_update_profile` AJAX actions. This is due to the `six_storage_getUserInfo()` and `six_storage_updateProfile()` functions being registered on `wp_ajax_nopriv_*` hooks and accepting a tenant identifier directly from `$_POST['userId']` without performing any ownership verification, session binding, or nonce validation to confirm the requester has a legitimate relationship to the supplied ID. This makes it possible for unauthenticated attackers to read and modify arbitrary tenants' profile data — including name, email address, phone number, physical address, and SSN — by supplying an enumerated `userId` value in a crafted request to either handler.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
12 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 8, 2026 to June 14, 2026)Wordfence
Engine Newsletters The Events Calendar 6.15.12-6.16.2 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-49772 Patch Status Patched Published Jun 8, 2026 Affected Software The Events Calendar [the-events-calendar] Researcher vtim More Details > WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. WP Maps – Googl
vendorwww.wordfence.comJun 18, 2026, 5:31 PM - https://www.wordfence.com/threat-intel/vulnerabilities/id/74fa4240-6f62-4db6-b7e7-56998fc29e42?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJun 9, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/6storage-rentals/tags/2.22.0/inc/Base/Six_Storage_DashboardController.php#L998plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 9, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/6storage-rentals/tags/2.22.0/inc/Base/Six_Storage_DashboardController.php#L995plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 9, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/6storage-rentals/tags/2.22.0/inc/Base/Six_Storage_DashboardController.php#L1955plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 9, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/6storage-rentals/tags/2.22.0/inc/Base/Six_Storage_DashboardController.php#L1931plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 9, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/6storage-rentals/tags/2.22.0/inc/Base/Six_Storage_DashboardController.php#L11plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 9, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/6storage-rentals/tags/2.20.2/inc/Base/Six_Storage_DashboardController.php#L998plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 9, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/6storage-rentals/tags/2.20.2/inc/Base/Six_Storage_DashboardController.php#L995plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 9, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/6storage-rentals/tags/2.20.2/inc/Base/Six_Storage_DashboardController.php#L1955plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 9, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/6storage-rentals/tags/2.20.2/inc/Base/Six_Storage_DashboardController.php#L1931plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 9, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/6storage-rentals/tags/2.20.2/inc/Base/Six_Storage_DashboardController.php#L11plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 9, 2026, 5:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-68501CVSS 6.5 · Medium
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectCon…
- CVE-2026-68500CVSS 7.5 · High
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment w…
- CVE-2026-10700CVSS 6.5 · Medium
IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The /api/v1/file…
- CVE-2026-12945CVSS 7.1 · High
IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthentica…
- CVE-2026-67348CVSS 8.6 · High
Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. A…
- CVE-2026-15257CVSS 5.3 · Medium
The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated…