First published: Mon May 09 2022(Updated: )
The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpgraphql Wpgraphql | <0.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-25060 is medium with a CVSS score of 5.3.
CVE-2019-25060 affects the WPGraphQL WordPress plugin before version 0.3.5.
CVE-2019-25060 allows a remote attacker to forge a GraphQL query to retrieve the account roles of every user on the affected site.
Yes, the fix for CVE-2019-25060 is available in version 0.3.5 of the WPGraphQL WordPress plugin.
Yes, you can find references for CVE-2019-25060 at the following links: [GitHub Pull Request](https://github.com/wp-graphql/wp-graphql/pull/900) and [WPScan Vulnerability Report](https://wpscan.com/vulnerability/393be73a-f8dc-462f-8670-f20ab89421fc).