1 vulnerability across 1 product scored HIGH or above on August 15, 2026.

  • ๐ŸŸ  HIGH: 1

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-17083 (ibm/i) โ€” F1: exploitable โ†’ functional, AAS: 10.9 โ†’ 12.9 (HIGH โ†’ CRITICAL). Originally in 2026-08-12 bulletin.
  • [UPGRADED] CVE-2026-72886 (dokploy/dokploy) โ€” F1: exploitable โ†’ functional, AAS: 10.1 โ†’ 12.1 (HIGH โ†’ CRITICAL). Originally in 2026-08-10 bulletin.
  • [UPGRADED] CVE-2026-72882 (dokploy/dokploy) โ€” F1: exploitable โ†’ functional, AAS: 10.1 โ†’ 12.1 (HIGH โ†’ CRITICAL). Originally in 2026-08-10 bulletin.
  • [UPGRADED] CVE-2026-72901 (dokploy/dokploy) โ€” F1: exploitable โ†’ functional, AAS: 10.1 โ†’ 12.1 (HIGH โ†’ CRITICAL). Originally in 2026-08-10 bulletin.
  • [UPGRADED] CVE-2026-72737 (dokploy/dokploy) โ€” F1: exploitable โ†’ functional, AAS: 9.7 โ†’ 11.7 (HIGH โ†’ HIGH). Originally in 2026-08-10 bulletin.

๐ŸŸ  [HIGH] sixstorage/6storage_rentals

1 CVE | CVSS 3.1: 9.8 | AAS 10.9

  • cpe:2.3:a:sixstorage:6storage_rentals:*:*:*:*:*:*:*:*

SixStorage 6Storage Rentals Plugin for WordPress

The 6Storage Rentals plugin for WordPress versions up to and including 2.27.0 is affected by one critical vulnerability (CVE-2026-15303, CVSS 9.8) that allows unauthenticated authentication bypass. The flaw exists in the six_storage_create_wp_user AJAX handler, which can be invoked without authentication and sets login cookies for any existing WordPress user based on an attacker-supplied email address, with no nonce, capability, or ownership checks. This effectively allows a remote attacker to log in as any user on the site, including administrators, without credentials.

WordPress site administrators using this plugin should treat this as an urgent priority. Update the 6Storage Rentals plugin beyond version 2.27.0 immediately, or deactivate and remove it if no patch is available. Review site access logs for unexpected calls to the affected AJAX endpoint and audit user sessions for signs of unauthorized access.

Vendor Advisory