CVE-2026-88974: Wp-Graphql

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status transitions. An authenticated Contributor can therefore publish the Contributor's own draft without editorial approval or modify the Contributor's previously published post despite lacking edit_published_posts, while posts owned by other authors remain protected. This issue is fixed in version 2.22.2.

Affected products

  • Wp-Graphql Wp-Graphql: before 2.22.2 (fixed in 2.22.2)

Published 2026-09-23. Last modified 2026-09-23.