[vulnfeed] 3 critical CVEs — 2026-08-15 04:00 UTC
vulnfeed
Critical alert — 2026-08-15 04:53 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-15303CRITICAL
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered
CVSS 9.8
CVE-2026-15341CRITICAL
The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account T
The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_session()` function,
CVSS 9.8
CVE-2026-14484CRITICAL
The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary fil
The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload function
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: