MEDIUM
wp-graphql
CVE published 2026-07-31
CVE-2026-54768
The WPGraphQL plugin for WordPress, from version 2.0.0 to 2.15.1, contains a vulnerability in the deprecated user field on SendPasswordResetEmailPayload. This allows an unauthenticated caller to distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. The issue is fixed in version 2.15.1. WPGraphQL users should review their configurations and [truncated]