PT-2019-19913 · WordPress · Wpgraphql

·

CVE-2019-9880

·

Published

2019-05-08

·

Updated

2025-09-18

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WPGraphQL version 0.2.3
Description An issue was discovered in the WPGraphQL plugin for WordPress, where an unauthenticated attacker can retrieve all WordPress users' details, including email address, role, and username, by querying the 'users' RootQuery.
Recommendations For WPGraphQL version 0.2.3, consider restricting access to the 'users' RootQuery until a patch is available. As a temporary workaround, disabling the users query in the RootQuery may help minimize the risk of exploitation.

Exploit

Fix

DoS

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9880

Affected Products

Wpgraphql