← back
CVE-2019-25060CWE-284

WP-GraphQL < 0.3.5 - Improper Access Control

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.8%
exploitation probability
1.8%top 24% of all CVEs
observed exploitation
nono source reports it
The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.
Affected products
Unknown · WPGraphQL