CVE-2019-9880: Critical severity wpengine wpgraphql vulnerability
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-9880?
CVE-2019-9880 is a vulnerability in the WPGraphQL 0.2.3 plugin for WordPress that allows an unauthenticated attacker to retrieve all WordPress user details.
How severe is CVE-2019-9880?
CVE-2019-9880 has a severity score of 9.1, which is classified as critical.
Which software version is affected by CVE-2019-9880?
WPGraphQL 0.2.3 is the affected version of the plugin.
How can an attacker exploit CVE-2019-9880?
By querying the 'users' RootQuery, an unauthenticated attacker can retrieve all WordPress user details such as email address, role, and username.
Is there a fix available for CVE-2019-9880?
Yes, a fix is available in WPGraphQL version 0.3.0, which should be updated to mitigate the vulnerability.