CVE-2019-9881: Wpengine Wpgraphql
Medium severity, CVSS 5.3. EPSS: 18.8% chance of exploitation in the next 30 days.
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.
Affected products
- Wpengine Wpgraphql: version 0.2.3 only
Published 2019-06-10. Last modified 2026-06-17.