cleantalk
Vulnerabilities and Security Researches

GEO my WordPress, CVE-2026-15260

CVE, Research URL

CVE-2026-15260

Application

GEO my WordPress

Published on
Aug 03, 2026
Research Description
The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.
Affected versions
max 4.5.5.3.
Status
vulnerable