GEO my WordPress, CVE-2026-15260
- CVE, Research URL
- Home page URL
- Application
- Published on
- Aug 03, 2026
- Research Description
- The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.
- Affected versions
-
max 4.5.5.3.
- Status
-
vulnerable