CVE-2019-9880

CRITICAL EXPLOITED IN THE WILD NUCLEI

WPGraphQL 0.2.3 - Unauthenticated Information Disclosure via Users RootQuery

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-9880 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit. A Nuclei detection template is also available.

AI-analyzed exploit summary This Python script exploits multiple vulnerabilities in wp-graphql (CVE-2019-9879, CVE-2019-9880, CVE-2019-9881) to perform unauthorized actions such as posting comments as arbitrary users and registering admin accounts. It also includes functionality to enumerate plugins, themes, media, users, comments, and password-protected posts.

Description

An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

Exploits (1)

exploitdb WORKING POC
pythonwebappsphp
https://www.exploit-db.com/exploits/46886

This Python script exploits multiple vulnerabilities in wp-graphql (CVE-2019-9879, CVE-2019-9880, CVE-2019-9881) to perform unauthorized actions such as posting comments as arbitrary users and registering admin accounts. It also includes functionality to enumerate plugins, themes, media, users, comments, and password-protected posts.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: wp-graphql <= 0.2.3
No auth needed
Prerequisites: Access to the wp-graphql endpoint
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Nuclei Templates (1)

WPEngine WPGraphQL 0.2.3 - Unauthenticated User Information Disclosure
CRITICALVERIFIEDby intelligent-ears
FOFA: body="/wp-content/plugins/wp-graphql/"

References (5)

Core 5

Scores

CVSS v3 9.1
EPSS 0.7289
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2021-04-12
InTheWild.io 2021-04-12
CWE
CWE-306
Status published
Products (1)
wpengine/wpgraphql 0.2.3
Published Jun 10, 2019
Tracked Since Feb 18, 2026