First published: Fri Jun 30 2023(Updated: )
Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/wp-graphql/wp-graphql | <=1.14.5 | 1.14.6 |
Wpgraphql Wpgraphql | <=1.14.5 | |
Wpengine Wpgraphql | <=1.14.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this WordPress WPGraphQL vulnerability is CVE-2023-23684.
Users with capabilities to upload media are susceptible to Server Side Request Forgery (SSRF) when executing the createMediaItem Mutation.
WordPress WPGraphQL Plugin version 1.14.5 is affected by this vulnerability.
This vulnerability has a severity score of 6.5, which is categorized as medium.
To fix this vulnerability, update your WordPress WPGraphQL Plugin to version 1.14.6 or later.