CVE-2026-54768

WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in version 2.15.1.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-07-31 23:17

Updated : 2026-09-10 20:30


NVD link : CVE-2026-54768

Mitre link : CVE-2026-54768

CVE.ORG link : CVE-2026-54768


JSON object : View

Products Affected

No product.

CWE
CWE-204

Observable Response Discrepancy