First published: Mon Jun 10 2019(Updated: )
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wpgraphql Wpgraphql | =0.2.3 | |
Wpengine Wpgraphql | =0.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9880 is a vulnerability in the WPGraphQL 0.2.3 plugin for WordPress that allows an unauthenticated attacker to retrieve all WordPress user details.
CVE-2019-9880 has a severity score of 9.1, which is classified as critical.
WPGraphQL 0.2.3 is the affected version of the plugin.
By querying the 'users' RootQuery, an unauthenticated attacker can retrieve all WordPress user details such as email address, role, and username.
Yes, a fix is available in WPGraphQL version 0.3.0, which should be updated to mitigate the vulnerability.