Wpgraphql
WPGraphQL is a WordPress plugin that exposes GraphQL query interfaces to WordPress sites, and its modest vulnerability surface centers on a single product with recurring issues around improper access control to underlying content and user data. The observed weakness pattern reflects the plugin's role as a query gateway that must properly enforce WordPress's native permission model across exposed schema endpoints. Live severity, exploitation, and exposure counts are shown alongside this summary.
Trends Over Time
The number and severity of CVEs published that impact products developed by Wpgraphql over time
Products(1 total)
Top CVEs
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25060MEDIUM The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could | May 9, 2022 | 5.3 | 21 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this vendor scope (1 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpgraphql.
Media Mentions
Media articles that mention a CVE ID that affects a product developed by Wpgraphql — matched by CVE ID, not by vendor name.