MEDIUM 6.9 NVD
CVE-2026-54768
WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticate
WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in version 2.15.1.
References
- https://github.com/wp-graphql/wp-graphql/releases/tag/wp-graphql/v2.15.1
- https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-jhh7-832h-f8hv
- https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-jhh7-832h-f8hv
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-07-31 via NVD.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.