CVE-2026-54768

Summary

WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in version 2.15.1.

Affected Software

VendorProductVersion RangeStatus
wp-graphqlwp-graphql< 2.15.1affected

Weaknesses

  • CWE-204: CWE-204: Observable Response Discrepancy

References