PatchSiren

Wpgraphql CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Wpgraphql CVE published 2026-05-15

CVE-2021-47959

CVE-2021-47959 is a high-severity denial-of-service issue in WPGraphQL 1.3.5. According to the supplied record, an unauthenticated attacker can send batched GraphQL queries with duplicated fields to exhaust server resources, leading to out-of-memory conditions and MySQL connection errors. The supplied CVE record was published on 2026-05-15 and modified on 2026-05-18.