An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-06-10T17:32:39

Updated: 2019-06-10T17:34:37

Reserved: 2019-03-19T00:00:00


Link: CVE-2019-9880

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-06-10T18:29:01.143

Modified: 2024-01-22T15:39:41.963


Link: CVE-2019-9880

JSON object: View

cve-icon Redhat Information

No data.

CWE