wp-graphql/wp-graphql Security Advisories for v1.9.0 (3)
-
[MEDIUM] WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost
PKSA-8djr-jy87-r26y CVE-2026-88974 GHSA-5mmc-8pc9-wggg
Affected version: <2.22.2
Reported by:
GitHub -
[MEDIUM] WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)
PKSA-2dkq-4nxk-nkts CVE-2026-54768 GHSA-jhh7-832h-f8hv
Affected version: <=2.6.0
Reported by:
GitHub -
[MEDIUM] WPGraphQL Plugin vulnerable to Server Side Request Forgery (SSRF)
PKSA-ns74-hkjj-48kh CVE-2023-23684 GHSA-cfh4-7wq9-6pgg
Affected version: <=1.14.5
Reported by:
GitHub