WPGraphQL

WPGraphQL is a free, open-source WordPress plugin that provides an extendable GraphQL schema and API for any WordPress site. It allows developers to use the frameworks and tools they love and works great with Gatsby, Apollo Client, NextJS, and more. With GraphQL, the client makes declarative queries, asking for the exact data needed, and in exactly what was asked for is given in response, allowing for more efficient resource fetching. GraphQL queries also allow access to multiple root resources and smoothly follow references between connected resources.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in WPGraphQL 1.14.5

    Fixed

    The WPGraphQL plugin for WordPress is not secure in versions up to 1.14.5. An attacker with access to an editor or higher account can make requests to any web location from the web application that c...

    Read More
  • Denial of Service vulnerability in WPGraphQL 1.3.5

    Fixed

    The WPGraphQL plugin for WordPress has a security issue in versions up to and including 1.3.5. An unauthenticated attacker can cause a lot of damage by rapidly duplicating fields and queries

    Read More
  • Access violation vulnerability in WPGraphQL 0.2.3

    Fixed

    An issue was found in WPGraphQL up to version 0.2.3. Someone without permission could use a special type of query to get details about all the WordPress users

    Read More
  • Access violation vulnerability in WPGraphQL 0.3.4

    Fixed

    The WPGraphQL WordPress plugin

    Read More
  • Access violation vulnerability in WPGraphQL 0.2.3

    Fixed

    Using WPGraphQL up to version 0.2.3 with WordPress

    Read More
  • Access violation vulnerability in WPGraphQL 0.2.3

    Fixed

    WordPress versions up to 0.2.3 have a security issue which allows people with malicious intentions to create a new user account with administrative privileges. This happens when new user registrations...

    Read More