CVE-2026-15260
Received Received - Intake

Unauthorized Geolocation Record Modification in GEO my WP WordPress Plugin

Vulnerability report for CVE-2026-15260, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: WPScan

Description

The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
geo_my_wp geo_my_wp to 4.5.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the GEO my WP WordPress plugin versions before 4.5.5.3. It allows users with subscriber-level access or higher to modify or permanently delete geolocation records of other users or posts without proper ownership or capability checks.

Detection Guidance

Check for unauthorized modifications to geolocation records by reviewing WordPress database tables for unexpected changes. Inspect AJAX logs for suspicious activity from subscriber-level users targeting geolocation-related endpoints.

Impact Analysis

If you use this plugin, attackers with basic user access could alter or delete geolocation data of other users or posts. This could lead to misinformation, loss of critical location data, or disruption of services relying on accurate geolocation information.

Mitigation Strategies

Update the GEO my WP plugin to version 4.5.5.3 or later immediately. Temporarily restrict subscriber-level users from accessing admin-ajax.php or implement additional capability checks until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15260. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart