Wpgraphql
Wpengine · 5 CVEs
CVE-2022-1563
MEDIUM
WPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosure
Jan 16, 2024
CVE-2023-23684
MEDIUM
WordPress WPGraphQL Plugin <= 1.14.5 is vulnerable to Server Side Request Forgery (SSRF)
Nov 13, 2023
CVE-2019-9881
MEDIUM
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on…
Jun 10, 2019
CVE-2019-9880
CRITICAL
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible,…
Jun 10, 2019
CVE-2019-9879
CRITICAL
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever…
Jun 10, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2022-1563 | WPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosure | MEDIUM | 0.72% | Jan 16, 2024 |
| CVE-2023-23684 | WordPress WPGraphQL Plugin <= 1.14.5 is vulnerable to Server Side Request Forgery (SSRF) | MEDIUM | 0.45% | Nov 13, 2023 |
| CVE-2019-9881 | The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment'… | MEDIUM | 18.83% | Jun 10, 2019 |
| CVE-2019-9880 | An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to ret… | CRITICAL | 35.64% | Jun 10, 2019 |
| CVE-2019-9879 | The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. Thi… | CRITICAL | 46.61% | Jun 10, 2019 |
Showing 1 to 5 of 5 CVEs