CVE-2019-9880
CRITICAL EXPLOITED IN THE WILD NUCLEIWPGraphQL 0.2.3 - Unauthenticated Information Disclosure via Users RootQuery
Title source: llmExploitation Summary
CVE-2019-9880 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit. A Nuclei detection template is also available.
AI-analyzed exploit summary This Python script exploits multiple vulnerabilities in wp-graphql (CVE-2019-9879, CVE-2019-9880, CVE-2019-9881) to perform unauthorized actions such as posting comments as arbitrary users and registering admin accounts. It also includes functionality to enumerate plugins, themes, media, users, comments, and password-protected posts.
Description
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.
Exploits (1)
This Python script exploits multiple vulnerabilities in wp-graphql (CVE-2019-9879, CVE-2019-9880, CVE-2019-9881) to perform unauthorized actions such as posting comments as arbitrary users and registering admin accounts. It also includes functionality to enumerate plugins, themes, media, users, comments, and password-protected posts.
Nuclei Templates (1)
body="/wp-content/plugins/wp-graphql/"
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N