CVE-2026-15260: Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR
The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15260?
The severity of CVE-2026-15260 is classified as medium with a CVSS score of 4.3.
How do I fix CVE-2026-15260?
To fix CVE-2026-15260, update the Geo My WP plugin to version 4.5.5.3 or later.
What risks does CVE-2026-15260 pose?
CVE-2026-15260 allows users with subscriber-level access or higher to modify or delete geolocation records of other users, posing data integrity risks.
Which versions of Geo My WP are affected by CVE-2026-15260?
Geo My WP versions prior to 4.5.5.3 are affected by CVE-2026-15260.
What type of vulnerability is CVE-2026-15260?
CVE-2026-15260 is an IDOR (Insecure Direct Object Reference) vulnerability.