Incorrect authorization in WPGraphQL - CVE-2026-88974

 

Incorrect authorization in WPGraphQL - CVE-2026-88974

Published: September 7, 2026 / Updated: September 28, 2026


Vulnerability identifier: #VU147235
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-88974
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to publish and modify their own posts without required capabilities.

The vulnerability exists due to incorrect authorization in the updatePost mutation when processing GraphQL post-update requests. A remote user can submit an updatePost mutation to publish their own draft posts or modify their own previously published posts without the required capabilities to publish or edit published posts.

The issue is limited to posts owned by the Contributor.


Affected software

WPGraphQL

How to mitigate CVE-2026-88974

Install security update from vendor's website.

WPGraphQL - update to 2.22.2

External References

Related Security Bulletins