Impact
This vulnerability is a missing authorization flaw in the 6Storage Rentals WordPress plugin. Because the plugin does not enforce proper access controls, an attacker can craft URLs that traverse the file system and read files outside the intended plugin directory. The weakness falls under CWE-862, which describes unauthorized access to otherwise protected resources.
Affected Systems
Any WordPress site that installs 6Storage Rentals version 2.20.2 or earlier is potentially affected. The advisory lists no explicit lower bound, so all releases up to and including 2.20.2 are impacted.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability is classified as moderate severity. The EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation. The issue is not listed in CISA’s KEV catalog. The likely attack vector is via the web application, with the attacker possibly acting as an unauthenticated user, submitting a request that triggers the path traversal logic within the plugin.
OpenCVE Enrichment
EUVD