Record summary

CVE-2019-9881 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 12, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin WPGraphQL 0.2.3 - Multiple VulnerabilitiesExploitDB exploitby Simone QuatriniNot analyzed1 file

linked to 3 vulnerabilities

ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWPEngine WPGraphQL 0.2.3 - Unauthenticated Comment PostingCVSS 5.3

The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.

Impact

An attacker can exploit this vulnerability to post unauthorized comments on WordPress posts, potentially leading to content manipulation and defacement.

Remediation

Update WPGraphQL to version 0.3.0 or later to fix this vulnerability.

WeaknessesCWE-306
Authorsintelligent-ears
Template tagscvecve2019wpwp-pluginwordpresswp-graphqlwpengineunauthvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CPE: cpe:2.3:a:wpengine:wpgraphql:0.2.3:*:*:*:*:wordpress:*:*
Shodan: http.title:"WordPress" "graphql"
FOFA: body="/wp-content/plugins/wp-graphql/"

Source: ProjectDiscovery

References

6