CVE-2026-54768: Wp-Graphql
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in version 2.15.1.
Affected products
- Wp-Graphql Wp-Graphql: before 2.15.1 (fixed in 2.15.1)
Published 2026-07-31. Last modified 2026-09-10.