VendorsWP Enginewpgraphqlall versions
Vulnerabilities

WP Engine WPGraphQL

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2019-9879
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.
Published 2019-06-10 · Modified
9.81 PoCEPSS 0.466
CVE-2019-9880
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.
Published 2019-06-10 · Modified
9.11 PoCEPSS 0.348
CVE-2023-23684
WordPress WPGraphQL Plugin <= 1.14.5 is vulnerable to Server Side Request Forgery (SSRF)
Published 2023-11-13 · Modified
6.5EPSS 0.005
CVE-2019-9881
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.
Published 2019-06-10 · Modified
5.31 PoCEPSS 0.188
CVE-2022-1563
WPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosure
Published 2024-01-16 · Modified
5.3EPSS 0.007