Impact
The vulnerability allows unauthenticated users to inject arbitrary SQL statements into the database. This flaw originates from an input handling weakness classified as CWE-89. An attacker could read, modify, or delete sensitive data stored in the database, potentially compromising the confidentiality, integrity, and availability of the WordPress site.
Affected Systems
The flaw exists in the WordPress WPGraphQL plugin on all versions earlier than 2.11.1. Systems running this plugin, regardless of WordPress core version, are at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate severity, but the low EPSS score (<1%) suggests that exploitation is unlikely at present. Since the vulnerability is not listed in the CISA KEV catalog, there are currently no known large‑scale exploit campaigns. Nonetheless, unauthenticated attackers can exploit the flaw via public HTTP requests, so administrators should prioritize patching immediately.
OpenCVE Enrichment