5.4
CVE-2026-88974
- EPSS 0.28%
- Veröffentlicht 23.09.2026 14:11:06
- Zuletzt bearbeitet 23.09.2026 18:12:04
- Erkennungen
WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost
WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status transitions. An authenticated Contributor can therefore publish the Contributor's own draft without editorial approval or modify the Contributor's previously published post despite lacking edit_published_posts, while posts owned by other authors remain protected. This issue is fixed in version 2.22.2.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerwp-graphql
≫
Produkt
wp-graphql
Version
< 2.22.2
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.177 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-5mmc-8pc9-wggg
https://github.com/wp-graphql/wp-graphql/pull/4270
https://github.com/wp-graphql/wp-graphql/commit/55441663eaa33c3f2e05de038c8286c845916461
https://github.com/wp-graphql/wp-graphql/releases/tag/wp-graphql%2Fv2.22.2