CVE-2026-15260 PUBLISHED

Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR

Assigner: WPScan
Reserved: 09.07.2026 Published: 03.08.2026 Updated: 03.08.2026

The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.

Product Status

Vendor Unknown
Product GEO my WP
Versions Default: unaffected
  • affected from 0 to 4.5.5.3 (excl.)

Credits

  • Yaswanth Reddy Sunkara finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE