SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15260

MEDIUM · CVSS 4.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The GEO my WP plugin for WordPress prior to version 4.5.5.3 is vulnerable due to a lack of ownership and capability checks on specific AJAX actions, enabling authenticated users with subscriber-level access or higher to manipulate or delete geolocation records of other users and posts by providing arbitrary record IDs. This vulnerability could lead to unauthorized data modification and potential privacy breaches. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-15260
Severity
MEDIUM
CVSS
4.3
EPSS
0.15%
WordPress

Original NVD Description

The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.