WordPress · Wpgraphql Smart Cache · CVE-2026-92099
**Name of the Vulnerable Software and Affected Versions**
WPGraphQL Smart Cache versions prior to 2.3.2
**Description**
The plugin fails to require authorization or validate the caller-supplied query identifier when storing a persisted query from a request. This allows unauthenticated users to publish arbitrary query documents and claim query aliases before the site's own frontend registers them.
**Recommendations**
Update to version 2.3.2 or later.