PKSA-8djr-jy87-r26y Security Advisory
-
[MEDIUM] WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost
PKSA-8djr-jy87-r26y CVE-2026-88974 GHSA-5mmc-8pc9-wggg
Affected package: wp-graphql/wp-graphql
Affected version: <2.22.2
Reported by:
GitHub