CVE-2026-62102
moderateSubscriber Privilege Escalation in Gato GraphQL WordPress Plugin
CVE-2026-62102 is a privilege escalation flaw (CWE-266) in the Gato GraphQL plugin for WordPress that lets an authenticated user with Subscriber-level privileges elevate their account to higher privileges, most likely administrator. It is triggered over the web through the plugin's exposed GraphQL API, requiring only a low-privileged account (PR:L) and no user interaction, which is reflected in the 8.8 High CVSS 3.1 score. A successful attacker gains high-impact control over the site, consistent with administrator-level access to content, settings, and data. Any WordPress installation running Gato GraphQL version 19.2.3 or earlier is affected, with the greatest exposure on sites that permit subscriber registrations or have other subscriber-level accounts. As of this analysis there is no public proof-of-concept, the issue is not listed in CISA KEV, and no in-the-wild exploitation has been reported.
What to do: Update Gato GraphQL on every affected site to a release newer than 19.2.3, checking the plugin's changelog for the patched version. Until patched, consider deactivating the plugin if it is not required or restricting access to the GraphQL endpoint, and audit user accounts for unexpected administrator-level users (a sign of prior privilege escalation). Sites with registration closed and no subscriber-level accounts face reduced risk because exploitation requires an authenticated low-privileged user.
| Gato GraphQL (WordPress plugin) | <= 19.2.3 (all versions through 19.2.3) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-266
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.