Unauthenticated Post Publishing Vulnerability in WPGraphQL for WordPress
CVE-2026-88974
5.4MEDIUM
What is CVE-2026-88974?
WPGraphQL allows WordPress sites to utilize a GraphQL API, but versions prior to 2.22.2 contain a significant flaw in the updatePost mutation. This defect enables an authenticated Contributor to publish their own drafts without needing editorial approval or the proper permissions, specifically bypassing the object-level edit_post capability. Moreover, the Contributor can modify their previously published posts without possessing the edit_published_posts capability. This oversight poses a risk as it can lead to unauthorized changes within the site, while still protecting posts owned by other authors. The issue has been rectified in version 2.22.2.
Affected Version(s)
wp-graphql < 2.22.2