WPGraphQL <= 0.2.3 - Information Exposure
2019-05-08 00:00
Simone QuatriniStrategic Overview
StatusPatched in 0.3.0
Affected PluginWPGraphQL
Affected Version
<= 0.2.3CVSS9.1Critical
CVE
CVE-2019-9880Vulnerability Overview
An issue was discovered in WPGraphQL up to 0.2.3 . By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.
Technical Analysis
REMEDIATION: Update to version 0.3.0, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C