Incorrect default permissions in WPGraphQL for ACF - #VU148859
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to incorrect default permissions in the ACF Options Pages schema registration when processing GraphQL queries for PHP-registered Options Pages without a show_in_graphql setting. A remote attacker can query exposed Options Page metadata and stored field values to disclose sensitive information.
Exposure of stored field values requires an assigned ACF field group to be shown in GraphQL and both WPGraphQL and WPGraphQL for ACF to be active.