The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.22.0 via the `userId` parameter of the `six_storage_get_user_info` and `six_storage_update_profile` AJAX actions. This is due to the `six_storage_getUserInfo()` and `six_storage_updateProfile()` functions being registered on `wp_ajax_nopriv_*` hooks and accepting a tenant identifier directly from `$_POST['userId']` without performing any ownership verification, session binding, or nonce validation to confirm the requester has a legitimate relationship to the supplied ID. This makes it possible for unauthenticated attackers to read and modify arbitrary tenants' profile data — including name, email address, phone number, physical address, and SSN — by supplying an enumerated `userId` value in a crafted request to either handler.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 09 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sixstorage
Sixstorage 6storage Rentals Wordpress Wordpress wordpress |
|
| Vendors & Products |
Sixstorage
Sixstorage 6storage Rentals Wordpress Wordpress wordpress |
Tue, 09 Jun 2026 04:45:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-06-09T15:13:19.602Z
Reserved: 2026-05-21T14:57:48.503Z
Link: CVE-2026-9185
Updated: 2026-06-09T15:01:48.145Z
Status : Deferred
Published: 2026-06-09T05:16:41.213
Modified: 2026-06-09T13:33:34.393
Link: CVE-2026-9185
No data.
OpenCVE Enrichment
Updated: 2026-06-09T08:56:06Z
Weaknesses