plugin

Wp Graphql Vulnerabilities

17 known security issues reported for the Wp Graphql WordPress plugin. Most recent disclosed May 7, 2026.

2 critical 1 high 7 medium

Running Wp Graphql on your site? Check whether your installed version is affected.

Scan your site free

WPGraphQL <= 2.5.3 - Cross-Site Request Forgery

medium

The WPGraphQL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a...

CVSS:
4.3
Affected:
up to 2.5.3
Fixed in:
2.5.4
Disclosed:
May 7, 2026

CVE-2025-68604 on NVD →

WPGraphQL < 2.11.1 - Unauthenticated SQL Injection

high

The WPGraphQL plugin for WordPress is vulnerable to SQL Injection in versions up to 2.11.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing...

CVSS:
7.5
Affected:
up to 2.11.1
Fixed in:
2.11.1
Disclosed:
Apr 21, 2026

CVE-2026-40762 on NVD →

WPGraphQL - Broken Access Control vulnerability

medium

Broken Access Control vulnerability

CVSS:
5.4
Affected:
up to 2.9.1
Fixed in:
2.10
Disclosed:
Mar 24, 2026

WPGraphQL <= 2.9.1 - Missing Authorization

medium

The WPGraphQL plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.9.1
Fixed in:
2.10
Disclosed:
Mar 24, 2026

CVE-2026-33290 on NVD →

WPGraphQL [wp-graphql] < 1.14.6

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5.

Affected:
up to 1.14.6
Fixed in:
1.14.6
Disclosed:
Nov 13, 2023

CVE-2023-23684 on NVD →

WPGraphQL <= 1.14.5 - Authenticated (Editor+) Server-Side Request Forgery

medium

The WPGraphQL plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.14.5 via createMediaItem. This can allow authenticated attackers with editor access or higher to make web requests to arbitrary locations originating from the web application and can be used to query and...

CVSS:
5.5
Affected:
up to 1.14.5
Fixed in:
1.14.6
Disclosed:
Jun 28, 2023

CVE-2023-23684 on NVD →

WPGraphQL [wp-graphql] < 0.3.5

unknown

[en] The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.

Affected:
up to 0.3.5
Fixed in:
0.3.5
Disclosed:
May 9, 2022

CVE-2019-25060 on NVD →

WPGraphQL <= 1.3.5 - Denial of Service

medium

The WPGraphQL plugin for WordPress is vulnerable to Denial of Service via field duplication in versions up to, and including, 1.3.5. This makes it possible for unauthenticated attackers to rapidly duplicate fields and queries resulting in OOM and MySQL connection errors.

CVSS:
5.3
Affected:
up to 1.3.5
Fixed in:
1.3.6
Disclosed:
Apr 27, 2021

CVE-2021-31157 on NVD →

WPGraphQL <= 0.3.4 - Information Exposure

medium

The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.

CVSS:
6.5
Affected:
up to 0.3.4
Fixed in:
0.3.5
Disclosed:
Jul 10, 2019

CVE-2019-25060 on NVD →

WPGraphQL [wp-graphql] < 0.3.0

unknown

[en] The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.

Affected:
up to 0.3.0
Fixed in:
0.3.0
Disclosed:
Jun 10, 2019

CVE-2019-9879 on NVD →

WPGraphQL [wp-graphql] < 0.3.0

unknown

[en] An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

Affected:
up to 0.3.0
Fixed in:
0.3.0
Disclosed:
Jun 10, 2019

CVE-2019-9880 on NVD →

WPGraphQL [wp-graphql] < 0.3.0

unknown

[en] The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.

Affected:
up to 0.3.0
Fixed in:
0.3.0
Disclosed:
Jun 10, 2019

CVE-2019-9881 on NVD →

WPGraphQL [wp-graphql] < 0.3.0

unknown

Multiple Vulnerabilities found in WordPress WPGraphQL plugin (versions <= 0.2.3).

Affected:
up to 0.3.0
Fixed in:
0.3.0
Disclosed:
May 22, 2019

WPGraphQL <= 0.2.3 - Administrative User Creation

critical

The WPGraphQL versions up to 0.2.3 for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.

CVSS:
9.8
Affected:
up to 0.2.3
Fixed in:
0.3.0
Disclosed:
May 8, 2019

CVE-2019-9879 on NVD →

WPGraphQL <= 0.2.3 - Information Exposure

critical

An issue was discovered in WPGraphQL up to 0.2.3 . By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

CVSS:
9.1
Affected:
up to 0.2.3
Fixed in:
0.3.0
Disclosed:
May 8, 2019

CVE-2019-9880 on NVD →

WPGraphQL <= 0.2.3 - Unauthenticated Comment Creation

medium

The createComment mutation in WPGraphQL up to version 0.2.3 for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.

CVSS:
5.3
Affected:
up to 0.2.3
Fixed in:
0.3.0
Disclosed:
May 8, 2019

CVE-2019-9881 on NVD →

WPGraphQL [wp-graphql] < 1.3.6

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.3.6
Fixed in:
1.3.6

CVE-2021-31157 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database