Executive brief
CVE-2026-16249 was assigned to a vulnerability in the 6Storage Rentals WordPress plugin but was later rejected as a duplicate of CVE-2026-15303. This administrative issue means the vulnerability has two CVE identifiers pointing to the same flaw, which can create confusion when tracking and referencing the security issue. Users and security systems should use CVE-2026-15303 as the authoritative identifier.
Technical details
CVE-2026-16249 is an administrative duplicate—two CVE identifiers were mistakenly assigned to the same underlying vulnerability in the 6Storage Rentals WordPress plugin. The CVE program rejected this ID and designated CVE-2026-15303 as the canonical identifier for the flaw. No technical details about the actual vulnerability are available in this advisory, as it only documents the duplicate assignment issue. Security teams should reference CVE-2026-15303 when researching, patching, or tracking this vulnerability to avoid confusion and ensure accurate correlation across security tools and databases.
Affected products
- 6Storage Rentals 6Storage Rentals
Timeline
- 2026-08-24: other: CVE-2026-16249 rejected as duplicate of CVE-2026-15303