Remote User Registration Vulnerability in WPGraphQL Plugin for WordPress
CVE-2019-9879

9.8CRITICAL

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
10 June 2019

Summary

The WPGraphQL plugin version 0.2.3 for WordPress has a critical vulnerability that allows remote attackers to exploit the registerUser mutation for unauthorized user registration. When user registrations are enabled, this flaw enables the attackers to create new accounts with administrative privileges, potentially granting full control over the affected WordPress site. It is crucial for users of this plugin to update to the latest version immediately to mitigate this security issue.

References

EPSS Score

21% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.