WordPress Plugin Vulnerabilities

Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR

Description

The plugin does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.

Proof of Concept

Affects Plugins

Fixed in 4.5.5.3

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Yaswanth Reddy Sunkara
Submitter
Yaswanth Reddy Sunkara
Verified
Yes

Timeline

Publicly Published
2026-07-24 (about 10 days ago)
Added
2026-07-24 (about 9 days ago)
Last Updated
2026-07-24 (about 9 days ago)

Other