peter bassill · operator
$ cve CVE-2019-9881 JSON

CVE-2019-9881 EXPLOIT

5.3
MEDIUM · CVSS 3.0 · EPSS 18.8% (pctl 97)

Patch early

A public exploit exists.

Description

The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.

Scoring

CVSS5.3 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS18.83% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploityes
Published2019-06-10
Last modified2026-06-17

Affected (1)

VendorProduct
wpenginewpgraphql

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD