CVE-2019-9880
Summary
| CVE | CVE-2019-9880 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-10 18:29:00 UTC |
| Updated | 2024-01-22 15:39:00 UTC |
| Description | An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release v0.3.0 · wp-graphql/wp-graphql · GitHub | CONFIRM | github.com | Release Notes, Third Party Advisory |
| snippets/wp-graphql0.2.3_exploit.py at master · pentestpartners/snippets · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| WordPress WPGraphQL 0.2.3 Authentication Bypass / Information Disclosure ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Pwning WordPress GraphQL | Pen Test Partners | MISC | www.pentestpartners.com | Exploit, Third Party Advisory |
| WPGraphQL <= 0.2.3 - Multiple Vulnerabilities | MISC | wpvulndb.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.