PatchSiren

wp-graphql CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM wp-graphql CVE published 2026-07-31

CVE-2026-54768

The WPGraphQL plugin for WordPress, from version 2.0.0 to 2.15.1, contains a vulnerability in the deprecated user field on SendPasswordResetEmailPayload. This allows an unauthenticated caller to distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. The issue is fixed in version 2.15.1. WPGraphQL users should review their configurations and [truncated]