PT-2019-19914 · WordPress · Wpgraphql

Simone Q

·

Published

2019-06-10

·

Updated

2025-09-18

·

CVE-2019-9881

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WPGraphQL version 0.2.3
Description The issue allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled, through the createComment mutation.
Recommendations For WPGraphQL version 0.2.3, consider disabling the createComment mutation until a patch is available to prevent unauthorized comment posting.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2019-9881

Affected Products

Wpgraphql