CVE-2019-9880

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
10/06/2019
Last modified:
22/01/2024

Description

An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wpengine:wpgraphql:0.2.3:*:*:*:*:wordpress:*:*