s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-88974

📛 CVE Title

WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost

Description

WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status transitions. An authenticated Contributor can therefore publish the Contributor's own draft without editorial approval or modify the Contributor's previously published post despite lacking edit_published_posts, while posts owned by other authors remain protected. This issue is fixed in version 2.22.2.

Overview

State
PUBLISHED
Assigner (CNA)
GitHub_M
CVSS severity
MEDIUM
CVSS score
CVSS 5.4 / 10 5.4 5.4 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Effective score
5.4 / 10 MEDIUM source: CNA overview
CWE(s)
CWE-863
Reserved
2026-09-10
Published
2026-09-23 14:11 UTC
Last updated
2026-09-23 16:21 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/88xxx/CVE-2026-88974.json

NVD / KEV / EPSS data refreshed 2026-09-24 04:32 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-85310
Assigner
GitHub_M
Published
Sep 23, 2026, 2:11:06 PM
Updated
Sep 23, 2026, 4:21:35 PM
EUVD base score (CVSS 3.1)
5.4 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
EUVD-reported EPSS
0.0000
Vendors
wp-graphql
Products
wp-graphql (< 2.22.2)
Aliases
GHSA-5mmc-8pc9-wggg

ENISA description: WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status transitions. An authenticated Contributor can therefore publish the Contributor's own draft without editorial approval or modify the Contributor's previously published post despite lacking edit_published_posts, while posts owned by other authors remain protected. This issue is fixed in version 2.22.2.

EUVD references (4)

Affected products (1)

VendorProductVersionsPlatforms
wp-graphql wp-graphql < 2.22.2 (affected)

Vendor references (4)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

Remediations (10)

  • web:cyberscoop.com

    Microsoft addressed 974 defects across its product suite, including two actively exploited zero-day vulnerabilities, in its monthly Patch Tuesday security program.

    2026-09-24 11:47 UTC
  • web:gist.github.com

    CVE-2026-88974 is an incorrect authorization vulnerability in the WPGraphQL plugin for WordPress. Due to a failure to perform object-level capability checks or validate status-transition requirements in the updatePost mutation handler, authenticated Contributor-level users can publish their own draft posts without editorial approval or modify ...

    2026-09-24 11:47 UTC
  • web:sec.cloudapps.cisco.com

    On September 16, 2026 , the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the ...

    2026-09-24 11:47 UTC
  • web:securityboulevard.com

    Microsoft's September Patch Tuesday addresses a record 974 CVEs , including two Windows flaws already exploited in attacks. The two exploited vulnerabilities allow local attackers to elevate privileges, and CISA has added both to its Known Exploited Vulnerabilities catalog. The release also includes 22 Critical Office-related vulnerabilities, including 12 that can be triggered just by ...

    2026-09-24 11:47 UTC
  • web:senserva.com

    Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.

    2026-09-24 11:47 UTC
  • web:tbreak.com

    Microsoft's September 2026 Patch Tuesday release fixes 974 Microsoft CVEs , including 723 vulnerabilities across Windows. Microsoft's release notes list two Windows flaws as having exploitation detected, giving users and IT teams a reason to move the update up the queue rather than leave it for the next convenient restart. The scale also continues a summer of unusually large Microsoft ...

    2026-09-24 11:47 UTC
  • web:www.action1.com

    Patch Tuesday is a scheduled release day for software patches, primarily used by Microsoft, to fix security vulnerabilities, bugs, and performance issues in its software products like Windows, Office, and Azure. It occurs monthly and aims to standardize the process of delivering security updates to ensure devices remain protected.

    2026-09-24 11:47 UTC
  • web:www.securityweek.com

    Microsoft on Tuesday rolled out a record number of patches, fixing 974 CVEs across its products, including two vulnerabilities exploited in the wild as zero-days. The first exploited zero-day, CVE - 2026 -85880, is a heap buffer overflow issue in the Windows Advanced Local Procedure Call (ALPC) that could allow a local attacker to gain System privileges. "An attacker who can execute code in a ...

    2026-09-24 11:47 UTC
  • web:www.splashtop.com

    Respond faster to high-risk vulnerabilities with Splashtop AEM September's record Patch Tuesday shows how quickly patch management becomes a prioritization and verification problem. IT teams need to identify exposed devices, deploy urgent updates, and confirm remediation without losing track of systems across distributed environments.

    2026-09-24 11:47 UTC
  • web:zecurit.com

    Get the complete breakdown of Microsoft's September 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .

    2026-09-24 11:47 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-88974.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-88974",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-23T16:21:07.871440Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-23T16:21:35.694Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-5mmc-8pc9-wggg"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "wp-graphql",
          "vendor": "wp-graphql",
          "versions": [
            {
              "status": "affected",
              "version": "< 2.22.2"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status transitions. An authenticated Contributor can therefore publish the Contributor's own draft without editorial approval or modify the Contributor's previously published post despite lacking edit_published_posts, while posts owned by other authors remain protected. This issue is fixed in version 2.22.2."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-863",
              "description": "CWE-863: Incorrect Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-23T14:11:06.092Z",
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M"
      },
      "references": [
        {
          "name": "https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-5mmc-8pc9-wggg",
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-5mmc-8pc9-wggg"
        },
        {
          "name": "https://github.com/wp-graphql/wp-graphql/pull/4270",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/wp-graphql/wp-graphql/pull/4270"
        },
        {
          "name": "https://github.com/wp-graphql/wp-graphql/commit/55441663eaa33c3f2e05de038c8286c845916461",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/wp-graphql/wp-graphql/commit/55441663eaa33c3f2e05de038c8286c845916461"
        },
        {
          "name": "https://github.com/wp-graphql/wp-graphql/releases/tag/wp-graphql%2Fv2.22.2",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/wp-graphql/wp-graphql/releases/tag/wp-graphql%2Fv2.22.2"
        }
      ],
      "source": {
        "advisory": "GHSA-5mmc-8pc9-wggg",
        "discovery": "UNKNOWN"
      },
      "title": "WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "cveId": "CVE-2026-88974",
    "datePublished": "2026-09-23T14:11:06.092Z",
    "dateReserved": "2026-09-10T16:02:31.341Z",
    "dateUpdated": "2026-09-23T16:21:35.694Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}