ZeroHour

CVE-2019-9880

PoC ×3
CVSS 3.0
9.1 critical
EPSS
35%p98
Published
()
Modified
Description

An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

Vendors
wpengine
Products
wpgraphql
Ecosystems
WordPress
Weakness
CWE-306
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news