CVE-2026-15260: Unknown Geo My Wp
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.
Affected products
- Unknown Geo My Wp: before 4.5.5.3 (fixed in 4.5.5.3)
Published 2026-08-03. Last modified 2026-08-26.