Incorrect default permissions in WPGraphQL for ACF - #VU148859

 

Incorrect default permissions in WPGraphQL for ACF - #VU148859

Published: September 9, 2026


Vulnerability identifier: #VU148859
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-276
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to incorrect default permissions in the ACF Options Pages schema registration when processing GraphQL queries for PHP-registered Options Pages without a show_in_graphql setting. A remote attacker can query exposed Options Page metadata and stored field values to disclose sensitive information.

Exposure of stored field values requires an assigned ACF field group to be shown in GraphQL and both WPGraphQL and WPGraphQL for ACF to be active.


Affected software

WPGraphQL for ACF

Remediation

Install security update from vendor's website.

WPGraphQL for ACF - update to 3.0.0

External References

Related Security Bulletins