CVE-2026-15260: Unknown Geo My Wp

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.

Affected products

  • Unknown Geo My Wp: before 4.5.5.3 (fixed in 4.5.5.3)

Published 2026-08-03. Last modified 2026-08-26.