SB2026090749 - Incorrect authorization in WPGraphQL
Published: September 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper authorization in the WPGraphQL UserMutation role-handling logic when processing a roles array in createUser or updateUser GraphQL mutations. A remote privileged user can submit a crafted mutation with the administrator role first in the roles array to escalate privileges.
The API may report that the role assignment was denied even though the role has already been applied.
Remediation
Install update from vendor's website.