PT-2019-19913 · WordPress · Wpgraphql

Simone Q08

·

Published

2019-06-10

·

Updated

2025-09-18

·

CVE-2019-9880

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WPGraphQL version 0.2.3
Description An issue was discovered in the WPGraphQL plugin for WordPress, where an unauthenticated attacker can retrieve all WordPress users' details, including email address, role, and username, by querying the 'users' RootQuery.
Recommendations For WPGraphQL version 0.2.3, consider restricting access to the 'users' RootQuery until a patch is available. As a temporary workaround, disabling the users query in the RootQuery may help minimize the risk of exploitation.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2019-9880

Affected Products

Wpgraphql