CVE-2019-25060: Wpgraphql

Medium severity, CVSS 5.3. EPSS: 1.8% chance of exploitation in the next 30 days.

The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.

Affected products

  • Wpgraphql Wpgraphql: before 0.3.5 (fixed in 0.3.5)

Published 2022-05-09. Last modified 2026-06-17.