SB2026090748 - Incorrect authorization in WPGraphQL
Published: September 7, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect authorization (CVE-ID: CVE-2026-88974)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to publish and modify their own posts without required capabilities.
The vulnerability exists due to incorrect authorization in the updatePost mutation when processing GraphQL post-update requests. A remote user can submit an updatePost mutation to publish their own draft posts or modify their own previously published posts without the required capabilities to publish or edit published posts.
The issue is limited to posts owned by the Contributor.
Remediation
Install update from vendor's website.