First published: Mon Jun 10 2019(Updated: )
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WPGraphQL | =0.2.3 | |
WPEngine WPGraphQL | =0.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2019-9879.
CVE-2019-9879 has a severity rating of critical (9.8).
CVE-2019-9879 allows remote attackers to register a new user with admin privileges when new user registrations are allowed in the WPGraphQL 0.2.3 plugin for WordPress.
Yes, a fix is available for CVE-2019-9879. Users should upgrade to version 0.3.0 of the WPGraphQL plugin for WordPress.
More information about CVE-2019-9879 can be found at the following references: [1] [2] [3].