
CVE-2026-15260 The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-… https://www.cve.org/CVERecord?id=CVE-2026-15260
Post summary
The post discloses that the GEO my WP plugin (v<4.5.5.3) has missing ownership checks on AJAX actions, creating a privilege‑escalation risk, with no evidence of exploitation or mitigation offered.

