CVE-2019-9881

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
10/06/2019
Last modified:
22/01/2024

Description

The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wpengine:wpgraphql:0.2.3:*:*:*:*:wordpress:*:*