Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Simone Q

Pesquisador dePen Test Partners
#17769de 53,632
15.1CVSS total
Vulnerabilidades · 2
Média
1
Crítica
1
PT-2019-19912
9.8
2019-06-10
WordPress · Wpgraphql · CVE-2019-9879
**Name of the Vulnerable Software and Affected Versions** WPGraphQL version 0.2.3 **Description** The issue allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the `registerUser` mutation. **Recommendations** For WPGraphQL version 0.2.3, update to a version that fixes this issue to prevent remote attackers from registering new users with admin privileges.
PT-2019-19914
5.3
2019-06-10
WordPress · Wpgraphql · CVE-2019-9881
**Name of the Vulnerable Software and Affected Versions** WPGraphQL version 0.2.3 **Description** The issue allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled, through the createComment mutation. **Recommendations** For WPGraphQL version 0.2.3, consider disabling the createComment mutation until a patch is available to prevent unauthorized comment posting.