Incorrect authorization in WPGraphQL - #VU147236
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper authorization in the WPGraphQL UserMutation role-handling logic when processing a roles array in createUser or updateUser GraphQL mutations. A remote privileged user can submit a crafted mutation with the administrator role first in the roles array to escalate privileges.
The API may report that the role assignment was denied even though the role has already been applied.