CVE-2026-88974 PUBLISHED

WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost

Assigner: GitHub_M
Reserved: 10.09.2026 Published: 23.09.2026 Updated: 23.09.2026

WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status transitions. An authenticated Contributor can therefore publish the Contributor's own draft without editorial approval or modify the Contributor's previously published post despite lacking edit_published_posts, while posts owned by other authors remain protected. This issue is fixed in version 2.22.2.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CVSS Score: 5.4

Product Status

Vendor wp-graphql
Product wp-graphql
Versions
  • Version < 2.22.2 is affected

References

Problem Types

  • CWE-863: Incorrect Authorization CWE