Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rohan Pagey

#22060of 53,633
10.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-11510
5.3
2024-01-16
WordPress · Wpgraphql Woocommerce · CVE-2022-1563
**Name of the Vulnerable Software and Affected Versions** WPGraphQL WooCommerce WordPress plugin versions prior to 0.12.4 **Description** The issue allows unauthenticated attackers to enumerate a shop's coupon codes and values via GraphQL. This can be done through `GraphQL` endpoints, potentially exposing sensitive information about the shop's coupons. **Recommendations** For versions prior to 0.12.4, update to version 0.12.4 or later to resolve the issue. As a temporary workaround, consider restricting access to GraphQL endpoints to minimize the risk of exploitation.
PT-2022-8282
5.3
2022-05-09
WordPress · Wpgraphql · CVE-2019-25060
**Name of the Vulnerable Software and Affected Versions** WPGraphQL WordPress plugin versions prior to 0.3.5 **Description** The issue allows a remote attacker to forge a GraphQL query and retrieve the account roles of every user on the site due to improper access restriction to user role information. **Recommendations** For WPGraphQL WordPress plugin versions prior to 0.3.5, update to version 0.3.5 or later to resolve the issue. As a temporary workaround, consider restricting access to GraphQL queries to minimize the risk of exploitation.