Wpgraphql

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 7
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-54768

    WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)

    Last Modified: Aug 03, 2026
    Published: Jul 31, 2026

    CVE-2026-40762

    WordPress WPGraphQL plugin < 2.11.1 - SQL Injection vulnerability

    Last Modified: Jun 16, 2026
    Published: Jun 15, 2026

    CVE-2021-47959

    WordPress Plugin WPGraphQL 1.3.5 Denial of Service

    Last Modified: May 15, 2026
    Published: May 15, 2026

    CVE-2025-68604

    WordPress WPGraphQL plugin <= 2.5.3 - Cross Site Request Forgery (CSRF) vulnerability

    Last Modified: May 07, 2026
    Published: May 07, 2026

    CVE-2026-33290

    WPGraphQL Repo's updateComment allows low-privileged authenticated users to change comment moderation status (comment_approved) without moderate_comments permission

    Last Modified: Apr 16, 2026
    Published: Mar 23, 2026
    Items Per Page
    Wpgraphql Vulnerabilities & Security CVEs | CVE-DB