WPGraphQL <= 0.3.4 - Information Exposure

2019-07-10 00:00
Rohan Pagey

Strategic Overview

Status
Patched in 0.3.5
Affected PluginWPGraphQL
Affected Version<= 0.3.4
CVSS6.5Medium
CVECVE-2019-25060
View all WPGraphQL vulnerabilities

Vulnerability Overview

The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.

Technical Analysis

REMEDIATION: Update to version 0.3.5, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C