VulnerabilityModified
CVE-2019-9880
By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.
CRITICAL 9.1EPSS 34.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 34.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 34.76% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- wpengine/wpgraphql
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/153025/WordPress-WPGraphQL-0.2.3-Authentication-Bypass-Information-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/pentestpartners/snippets/blob/master/wp-graphql0.2.3_exploit.pyExploit, Third Party Advisory
- https://github.com/wp-graphql/wp-graphql/releases/tag/v0.3.0Release Notes, Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9282Vendor Advisory
- https://www.pentestpartners.com/security-blog/pwning-wordpress-graphql/Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/153025/WordPress-WPGraphQL-0.2.3-Authentication-Bypass-Information-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/pentestpartners/snippets/blob/master/wp-graphql0.2.3_exploit.pyExploit, Third Party Advisory
- https://github.com/wp-graphql/wp-graphql/releases/tag/v0.3.0Release Notes, Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9282Vendor Advisory
- https://www.pentestpartners.com/security-blog/pwning-wordpress-graphql/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.