Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Simone Q08

Pesquisador dePen Test Partners
#27793de 53,635
9.1CVSS total
Vulnerabilidades · 1
PT-2019-19913
9.1
2019-06-10
WordPress · Wpgraphql · CVE-2019-9880
**Name of the Vulnerable Software and Affected Versions** WPGraphQL version 0.2.3 **Description** An issue was discovered in the WPGraphQL plugin for WordPress, where an unauthenticated attacker can retrieve all WordPress users' details, including email address, role, and username, by querying the 'users' RootQuery. **Recommendations** For WPGraphQL version 0.2.3, consider restricting access to the 'users' RootQuery until a patch is available. As a temporary workaround, disabling the `users` query in the RootQuery may help minimize the risk of exploitation.