Server-Side Request Forgery (SSRF) in WPGraphQL - #VU148860

 

Server-Side Request Forgery (SSRF) in WPGraphQL - #VU148860

Published: September 9, 2026


Vulnerability identifier: #VU148860
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access internal services and disclose sensitive information.

The vulnerability exists due to an incomplete list of disallowed inputs in the createMediaItem GraphQL mutation when processing filePath URLs that use DNS hostnames resolving to link-local addresses. A remote user can submit a crafted filePath URL using a DNS hostname that resolves to a link-local address to access internal services and disclose sensitive information.

On cloud hosts exposing IMDSv1, temporary cloud credentials may be exposed through the Media Library.


Affected software

WPGraphQL

Remediation

Install security update from vendor's website.

WPGraphQL - update to 2.22.3

External References

Related Security Bulletins