CVE-2026-62102: WordPress Gato GraphQL plugin <= 19.2.3 - Privilege Escalation vulnerability
Published Sep 11, 2026
·Updated
Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.
Affected Software
1 affected component
WordPress Gato GraphQL plugin<=19.2.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Gato GraphQL pluginto a version that resolves this vulnerability.Fixed in 19.2.4
Event History
Sep 11, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires an existing account with Subscriber-level privileges. No user interaction is required, and the attack can be performed remotely.
2
What impact could successful exploitation have?
Successful exploitation can result in privilege escalation and has high impacts on confidentiality, integrity, and availability. The provided vector indicates the scope remains unchanged.
3
Which plugin versions are affected?
Gato GraphQL plugin versions 19.2.3 and earlier are identified as affected.