CVE-2025-68604: WordPress WPGraphQL plugin <= 2.5.3 - Cross Site Request Forgery (CSRF) vulnerability
Published May 7, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery.
This issue affects WPGraphQL: from n/a through 2.5.3.
Affected Software
1 affected component
WPGraphQL WPGraphQL<=2.5.3
Remediation
Information
Update the WordPress WPGraphQL Plugin to the latest available version (at least 2.5.4).
Event History
May 7, 2026
CVE Published
via MITRE·07:40 AM
Data Sourced
via MITRE·07:40 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-68604?
CVE-2025-68604 is classified as a medium severity vulnerability due to its potential for Cross Site Request Forgery.
2
How do I fix CVE-2025-68604?
To fix CVE-2025-68604, update the WPGraphQL plugin to version 2.5.4 or later.
3
What does CVE-2025-68604 affect?
CVE-2025-68604 affects WPGraphQL versions up to and including 2.5.3.
4
What vulnerability type is CVE-2025-68604?
CVE-2025-68604 is a Cross Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2025-68604 be exploited remotely?
Yes, CVE-2025-68604 can be exploited remotely if an attacker tricks a user into executing aCSRF attack.