Remote User Registration Vulnerability in WPGraphQL Plugin for WordPress
CVE-2019-9879
9.8CRITICAL
Summary
The WPGraphQL plugin version 0.2.3 for WordPress has a critical vulnerability that allows remote attackers to exploit the registerUser
mutation for unauthorized user registration. When user registrations are enabled, this flaw enables the attackers to create new accounts with administrative privileges, potentially granting full control over the affected WordPress site. It is crucial for users of this plugin to update to the latest version immediately to mitigate this security issue.
References
EPSS Score
21% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved