CVE-2019-9879: Critical severity wpgraphql vulnerability
Published Jun 10, 2019
·Updated
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.
Affected Software
2 affected components
WPGraphQL WPGraphQL WordPress=0.2.3
Wpengine Wpgraphql Wordpress=0.2.3
Event History
Jun 10, 2019
CVE Published
via MITRE·05:28 PM
Data Sourced
via MITRE·05:28 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2019-9879.
2
What is the severity rating of CVE-2019-9879?
CVE-2019-9879 has a severity rating of critical (9.8).
3
How does CVE-2019-9879 affect the WPGraphQL plugin for WordPress?
CVE-2019-9879 allows remote attackers to register a new user with admin privileges when new user registrations are allowed in the WPGraphQL 0.2.3 plugin for WordPress.
4
Is there a fix available for CVE-2019-9879?
Yes, a fix is available for CVE-2019-9879. Users should upgrade to version 0.3.0 of the WPGraphQL plugin for WordPress.
5
Where can I find more information about CVE-2019-9879?
More information about CVE-2019-9879 can be found at the following references: [1] [2] [3].