Incorrect authorization in WPGraphQL - #VU147236

 

Incorrect authorization in WPGraphQL - #VU147236

Published: September 7, 2026


Vulnerability identifier: #VU147236
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper authorization in the WPGraphQL UserMutation role-handling logic when processing a roles array in createUser or updateUser GraphQL mutations. A remote privileged user can submit a crafted mutation with the administrator role first in the roles array to escalate privileges.

The API may report that the role assignment was denied even though the role has already been applied.


Affected software

WPGraphQL

Remediation

Install security update from vendor's website.

WPGraphQL - update to 2.22.1

External References

Related Security Bulletins