SB2026090748 - Incorrect authorization in WPGraphQL



SB2026090748 - Incorrect authorization in WPGraphQL

Published: September 7, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026090748
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incorrect authorization (CVE-ID: CVE-2026-88974)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to publish and modify their own posts without required capabilities.

The vulnerability exists due to incorrect authorization in the updatePost mutation when processing GraphQL post-update requests. A remote user can submit an updatePost mutation to publish their own draft posts or modify their own previously published posts without the required capabilities to publish or edit published posts.

The issue is limited to posts owned by the Contributor.


Remediation

Install update from vendor's website.