SB2026091001 - Incorrect default permissions in WPGraphQL for ACF
Published: September 10, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect default permissions (CVE-ID: N/A)
CWE-ID: CWE-276 - Incorrect Default Permissions
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to incorrect default permissions in the ACF Options Pages schema registration when processing GraphQL queries for PHP-registered Options Pages without a show_in_graphql setting. A remote attacker can query exposed Options Page metadata and stored field values to disclose sensitive information.
Exposure of stored field values requires an assigned ACF field group to be shown in GraphQL and both WPGraphQL and WPGraphQL for ACF to be active.
Remediation
Install update from vendor's website.