CVE-2026-88974
📛 CVE Title
WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost
Description
WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status transitions. An authenticated Contributor can therefore publish the Contributor's own draft without editorial approval or modify the Contributor's previously published post despite lacking edit_published_posts, while posts owned by other authors remain protected. This issue is fixed in version 2.22.2.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- GitHub_M
- CVSS severity
- MEDIUM
- CVSS score
- 5.4 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L- Effective score
- 5.4 / 10 MEDIUM source: CNA overview
- CWE(s)
-
CWE-863 - Reserved
- 2026-09-10
- Published
- 2026-09-23 14:11 UTC
- Last updated
- 2026-09-23 16:21 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/88xxx/CVE-2026-88974.json
NVD / KEV / EPSS data refreshed 2026-09-24 04:32 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-85310 - Assigner
- GitHub_M
- Published
- Sep 23, 2026, 2:11:06 PM
- Updated
- Sep 23, 2026, 4:21:35 PM
- EUVD base score (CVSS 3.1)
-
5.4 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L - EUVD-reported EPSS
- 0.0000
- Vendors
- wp-graphql
- Products
-
wp-graphql (< 2.22.2)
- Aliases
-
GHSA-5mmc-8pc9-wggg
ENISA description: WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status transitions. An authenticated Contributor can therefore publish the Contributor's own draft without editorial approval or modify the Contributor's previously published post despite lacking edit_published_posts, while posts owned by other authors remain protected. This issue is fixed in version 2.22.2.
EUVD references (4)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| wp-graphql | wp-graphql |
< 2.22.2 (affected)
|
— |
Vendor references (4)
References embedded in the original CVE record by the assigning CNA.
- https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-5mmc-8pc9-wggg x_refsource_CONFIRM
- https://github.com/wp-graphql/wp-graphql/pull/4270 x_refsource_MISC
- https://github.com/wp-graphql/wp-graphql/commit/55441663eaa33c3f2e05de038c8286c845916461 x_refsource_MISC
- https://github.com/wp-graphql/wp-graphql/releases/tag/wp-graphql%2Fv2.22.2 x_refsource_MISC
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
Remediations (10)
-
web:cyberscoop.com
Microsoft addressed 974 defects across its product suite, including two actively exploited zero-day vulnerabilities, in its monthly Patch Tuesday security program.
2026-09-24 11:47 UTC -
web:gist.github.com
CVE-2026-88974 is an incorrect authorization vulnerability in the WPGraphQL plugin for WordPress. Due to a failure to perform object-level capability checks or validate status-transition requirements in the updatePost mutation handler, authenticated Contributor-level users can publish their own draft posts without editorial approval or modify ...
2026-09-24 11:47 UTC -
web:sec.cloudapps.cisco.com
On September 16, 2026 , the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the ...
2026-09-24 11:47 UTC -
web:securityboulevard.com
Microsoft's September Patch Tuesday addresses a record 974 CVEs , including two Windows flaws already exploited in attacks. The two exploited vulnerabilities allow local attackers to elevate privileges, and CISA has added both to its Known Exploited Vulnerabilities catalog. The release also includes 22 Critical Office-related vulnerabilities, including 12 that can be triggered just by ...
2026-09-24 11:47 UTC -
web:senserva.com
Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.
2026-09-24 11:47 UTC -
web:tbreak.com
Microsoft's September 2026 Patch Tuesday release fixes 974 Microsoft CVEs , including 723 vulnerabilities across Windows. Microsoft's release notes list two Windows flaws as having exploitation detected, giving users and IT teams a reason to move the update up the queue rather than leave it for the next convenient restart. The scale also continues a summer of unusually large Microsoft ...
2026-09-24 11:47 UTC -
web:www.action1.com
Patch Tuesday is a scheduled release day for software patches, primarily used by Microsoft, to fix security vulnerabilities, bugs, and performance issues in its software products like Windows, Office, and Azure. It occurs monthly and aims to standardize the process of delivering security updates to ensure devices remain protected.
2026-09-24 11:47 UTC -
web:www.securityweek.com
Microsoft on Tuesday rolled out a record number of patches, fixing 974 CVEs across its products, including two vulnerabilities exploited in the wild as zero-days. The first exploited zero-day, CVE - 2026 -85880, is a heap buffer overflow issue in the Windows Advanced Local Procedure Call (ALPC) that could allow a local attacker to gain System privileges. "An attacker who can execute code in a ...
2026-09-24 11:47 UTC -
web:www.splashtop.com
Respond faster to high-risk vulnerabilities with Splashtop AEM September's record Patch Tuesday shows how quickly patch management becomes a prioritization and verification problem. IT teams need to identify exposed devices, deploy urgent updates, and confirm remediation without losing track of systems across distributed environments.
2026-09-24 11:47 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's September 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-09-24 11:47 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-88974.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-88974",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T16:21:07.871440Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T16:21:35.694Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-5mmc-8pc9-wggg"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "wp-graphql",
"vendor": "wp-graphql",
"versions": [
{
"status": "affected",
"version": "< 2.22.2"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status transitions. An authenticated Contributor can therefore publish the Contributor's own draft without editorial approval or modify the Contributor's previously published post despite lacking edit_published_posts, while posts owned by other authors remain protected. This issue is fixed in version 2.22.2."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863: Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T14:11:06.092Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-5mmc-8pc9-wggg",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-5mmc-8pc9-wggg"
},
{
"name": "https://github.com/wp-graphql/wp-graphql/pull/4270",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/wp-graphql/wp-graphql/pull/4270"
},
{
"name": "https://github.com/wp-graphql/wp-graphql/commit/55441663eaa33c3f2e05de038c8286c845916461",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/wp-graphql/wp-graphql/commit/55441663eaa33c3f2e05de038c8286c845916461"
},
{
"name": "https://github.com/wp-graphql/wp-graphql/releases/tag/wp-graphql%2Fv2.22.2",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/wp-graphql/wp-graphql/releases/tag/wp-graphql%2Fv2.22.2"
}
],
"source": {
"advisory": "GHSA-5mmc-8pc9-wggg",
"discovery": "UNKNOWN"
},
"title": "WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-88974",
"datePublished": "2026-09-23T14:11:06.092Z",
"dateReserved": "2026-09-10T16:02:31.341Z",
"dateUpdated": "2026-09-23T16:21:35.694Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}