CVE-2019-9879: Wpengine Wpgraphql

Critical severity, CVSS 9.8. EPSS: 46.6% chance of exploitation in the next 30 days.

The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.

Affected products

Published 2019-06-10. Last modified 2026-06-17.