CVE-2019-9880
critical · 9.1A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.
9.1
CVSS
34.8%
EPSS (exploit prob.)
98th
EPSS percentile
2019-06-10
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-306
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| wpengine | wpgraphql | 0.2.3 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/153025/WordPress-WPGraphQL-0.2.3-Authentication-Bypass-Information-Disclosure.html
- https://github.com/pentestpartners/snippets/blob/master/wp-graphql0.2.3_exploit.py
- https://github.com/wp-graphql/wp-graphql/releases/tag/v0.3.0
- https://wpvulndb.com/vulnerabilities/9282
- https://www.pentestpartners.com/security-blog/pwning-wordpress-graphql/
- http://packetstormsecurity.com/files/153025/WordPress-WPGraphQL-0.2.3-Authentication-Bypass-Information-Disclosure.html
- https://github.com/pentestpartners/snippets/blob/master/wp-graphql0.2.3_exploit.py
- https://github.com/wp-graphql/wp-graphql/releases/tag/v0.3.0
- https://wpvulndb.com/vulnerabilities/9282
- https://www.pentestpartners.com/security-blog/pwning-wordpress-graphql/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-9880