WPGraphQL <= 0.2.3 - Information Exposure

2019-05-08 00:00
Simone Quatrini

Strategic Overview

Status
Patched in 0.3.0
Affected PluginWPGraphQL
Affected Version<= 0.2.3
CVSS9.1Critical
CVECVE-2019-9880
View all WPGraphQL vulnerabilities

Vulnerability Overview

An issue was discovered in WPGraphQL up to 0.2.3 . By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

Technical Analysis

REMEDIATION: Update to version 0.3.0, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C