CVE-2019-25060: WP-GraphQL < 0.3.5 - Improper Access Control
The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25060?
The severity of CVE-2019-25060 is medium with a CVSS score of 5.3.
How does CVE-2019-25060 affect the WPGraphQL WordPress plugin?
CVE-2019-25060 affects the WPGraphQL WordPress plugin before version 0.3.5.
How does CVE-2019-25060 exploit work?
CVE-2019-25060 allows a remote attacker to forge a GraphQL query to retrieve the account roles of every user on the affected site.
Is there a fix available for CVE-2019-25060?
Yes, the fix for CVE-2019-25060 is available in version 0.3.5 of the WPGraphQL WordPress plugin.
Are there any references available for CVE-2019-25060?
Yes, you can find references for CVE-2019-25060 at the following links: [GitHub Pull Request](https://github.com/wp-graphql/wp-graphql/pull/900) and [WPScan Vulnerability Report](https://wpscan.com/vulnerability/393be73a-f8dc-462f-8670-f20ab89421fc).