CVE-2019-9880
CRITICAL 9.1EPSS 34.8%
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.
- CVSS v3.0
- 9.1 CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - CVSS v2.0
- 6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N - EPSS
- 34.76% chance of exploitation in the next 30 days, 98th percentile
- Nuclei
- critical · CWE-306
- Published
- 2019-06-10
- Updated
- 2024-11-15
Proof-of-concept exploits (2)
- http://packetstormsecurity.com/files/153025/WordPress-WPGraphQL-0.2.3-Authentication-Bypa…
- https://www.pentestpartners.com/security-blog/pwning-wordpress-graphql/