Incorrect authorization in WPGraphQL - CVE-2026-88974
Published: September 7, 2026 / Updated: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to publish and modify their own posts without required capabilities.
The vulnerability exists due to incorrect authorization in the updatePost mutation when processing GraphQL post-update requests. A remote user can submit an updatePost mutation to publish their own draft posts or modify their own previously published posts without the required capabilities to publish or edit published posts.
The issue is limited to posts owned by the Contributor.