CVE-2019-9881: Medium severity wpgraphql vulnerability
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-9881?
CVE-2019-9881 is a vulnerability in the WPGraphQL 0.2.3 plugin for WordPress that allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.
How severe is CVE-2019-9881?
CVE-2019-9881 has a severity keyword of 'medium' and a severity value of 5.3.
How can I fix CVE-2019-9881?
To fix CVE-2019-9881, upgrade to WPGraphQL version 0.3.0 or higher.
Where can I find more information about CVE-2019-9881?
You can find more information about CVE-2019-9881 at the following references: [http://packetstormsecurity.com/files/153025/WordPress-WPGraphQL-0.2.3-Authentication-Bypass-Information-Disclosure.html](http://packetstormsecurity.com/files/153025/WordPress-WPGraphQL-0.2.3-Authentication-Bypass-Information-Disclosure.html), [https://github.com/pentestpartners/snippets/blob/master/wp-graphql0.2.3_exploit.py](https://github.com/pentestpartners/snippets/blob/master/wp-graphql0.2.3_exploit.py), [https://github.com/wp-graphql/wp-graphql/releases/tag/v0.3.0](https://github.com/wp-graphql/wp-graphql/releases/tag/v0.3.0)
What is the CWE ID for CVE-2019-9881?
The CWE ID for CVE-2019-9881 is 306.