CVE-2026-15260
Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.
| Vendor | unknown |
| Product | geo my wp |
| Published | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown geo my wp
Be the first to know when new unknown vulnerabilities affecting unknown geo my wp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / GEO my WP
0 < 4.5.5.3
References
Credits
Yaswanth Reddy Sunkara WPScan