๐Ÿ” CVE Alert

CVE-2026-15260

MEDIUM 4.3

Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR

CVSS Score
4.3
EPSS Score
0.1%
EPSS Percentile
3th

The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.

Vendor unknown
Product geo my wp
Published Aug 3, 2026
Last Updated Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for unknown geo my wp

Be the first to know when new medium vulnerabilities affecting unknown geo my wp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / GEO my WP
0 < 4.5.5.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/6ba28169-0746-44a4-b622-1cd6b9a65608/

Credits

Yaswanth Reddy Sunkara WPScan